First published: Sat Jan 30 2016(Updated: )
The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID CSCul65330.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco 500 Series Switch Firmware | =1.2.0.92 | |
Cisco SF500-24MP | ||
Cisco SF500-24P Firmware | ||
Cisco SF500-48 Firmware | ||
Cisco SF500-48 Firmware | ||
Cisco SG500-28PP Firmware | ||
Cisco SG500-28MPP Firmware | ||
Cisco SG500-28P | ||
Cisco SG500-52 Firmware | ||
Cisco SG500-52 | ||
Cisco SG500-52P | ||
Cisco SG500X-24P | ||
Cisco SG500X-24P | ||
Cisco SG500X-48MP Firmware | ||
Cisco SG500X-48P | ||
Cisco SG500XG-8F8T Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1303 has a severity rating of Medium due to its denial of service impact on affected devices.
To fix CVE-2016-1303, upgrade the Cisco Small Business 500 devices firmware to a version higher than 1.2.0.92.
CVE-2016-1303 allows remote attackers to perform a denial of service attack via crafted HTTP requests.
CVE-2016-1303 affects Cisco Small Business 500 series devices running firmware version 1.2.0.92.
There are no documented workarounds for CVE-2016-1303; upgrading the firmware is the recommended action.