CVE-2017-6720: Buffer Overflow
A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition. The vulnerability is due to improper processing of SSH connections. An attacker could exploit this vulnerability by logging in to an affected switch via SSH and sending a malicious SSH message. This vulnerability affects the following Cisco products when SSH is enabled: Small Business 300 Series Managed Switches, Small Business 500 Series Stackable Managed Switches, 350 Series Managed Switches, 350X Series Stackable Managed Switches, 550X Series Stackable Managed Switches, ESW2 Series Advanced Switches. Cisco Bug IDs: CSCvb48377.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6720?
CVE-2017-6720 has been classified with a severity level that could result in a denial of service (DoS) condition.
How do I fix CVE-2017-6720?
To fix CVE-2017-6720, upgrade the affected Cisco Small Business Managed Switches software to a version greater than 1.4.8.06.
Which Cisco products are affected by CVE-2017-6720?
CVE-2017-6720 affects various Cisco Small Business Managed Switch models with firmware versions up to 1.4.8.06.
What type of attack does CVE-2017-6720 facilitate?
CVE-2017-6720 enables an authenticated, remote attacker to cause a reload of the affected switch.
Is CVE-2017-6720 easy to exploit?
CVE-2017-6720 requires authentication, which may limit the ease of exploitation to authorized users.