First published: Wed Oct 16 2019(Updated: )
A vulnerability in the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link and subsequently access a specific web interface page. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco SF250-24 Firmware | <2.5.0.90 | |
Cisco SF250-24 | ||
Cisco SF250-24P Firmware | <2.5.0.90 | |
Cisco SF250-24P Firmware | ||
Cisco SF250-48 Firmware | <2.5.0.90 | |
Cisco SF250-48 | ||
Cisco sf250-48hp firmware | <2.5.0.90 | |
Cisco sf250-48hp firmware | ||
Cisco SF250-08 Firmware | <2.5.0.90 | |
Cisco SF250-08 | ||
Cisco SF250-08HP | <2.5.0.90 | |
Cisco SF250-08HP | ||
Cisco sf250-10p | <2.5.0.90 | |
Cisco sf250-10p firmware | ||
Cisco SF250-18 Firmware | <2.5.0.90 | |
Cisco SF250-18 Firmware | ||
Cisco SF250-26 Firmware | <2.5.0.90 | |
Cisco SF250-26 Firmware | ||
Cisco SF250-26HP Firmware | <2.5.0.90 | |
Cisco SF250-26HP Firmware | ||
Cisco SF250-26P Firmware | <2.5.0.90 | |
Cisco SF250-26P | ||
Cisco SF250-50P Firmware | <2.5.0.90 | |
Cisco SF250-50P Firmware | ||
Cisco SF250-50HP Firmware | <2.5.0.90 | |
Cisco SF250-50HP Firmware | ||
Cisco SF250-50P Firmware | <2.5.0.90 | |
Cisco SF250-50P Firmware | ||
Cisco SF250X-24 Firmware | <2.5.0.90 | |
Cisco SF250X-24 | ||
Cisco SF250X-24P Firmware | <2.5.0.90 | |
Cisco SF250X-24P Firmware | ||
Cisco SF250X-48 Firmware | <2.5.0.90 | |
Cisco SF250X-48 Firmware | ||
Cisco SF250X-48P Firmware | <2.5.0.90 | |
Cisco SF250X-48P Firmware | ||
Cisco SG350-10 Firmware | <2.5.0.90 | |
Cisco SG350-10P | ||
Cisco SG350-10P | <2.5.0.90 | |
Cisco SG350-10P | ||
Cisco SG350-10MP Firmware | <2.5.0.90 | |
Cisco SG350-10MP | ||
Cisco SG355-10P | <2.5.0.90 | |
Cisco SG355-10P | ||
Cisco SG350-28 Firmware | <2.5.0.90 | |
Cisco SG350-28 | ||
Cisco SG350-28P Firmware | <2.5.0.90 | |
Cisco SG350-28P | ||
Cisco SG350-28MP Firmware | <2.5.0.90 | |
Cisco SG350-28MP | ||
Cisco SF350-48 Firmware | <2.5.0.90 | |
Cisco SF350-48P Firmware | ||
Cisco SF350-48P Firmware | <2.5.0.90 | |
Cisco SF350-48P Firmware | ||
Cisco SF350-48MP Firmware | <2.5.0.90 | |
Cisco SF350-48MP Firmware | ||
Cisco SX550X-16FT Firmware | <2.5.0.90 | |
Cisco SX550X-16FT | ||
Cisco SX550X-24FT Firmware | <2.5.0.90 | |
Cisco SX550X-24FT | ||
Cisco SX550X-12F Firmware | <2.5.0.90 | |
Cisco SX550X-12F Firmware | ||
Cisco SX550X-24F Firmware | <2.5.0.90 | |
Cisco SX550X-24F Firmware | ||
Cisco SX550X-24FT Firmware | <2.5.0.90 | |
Cisco SX550X-24 | ||
Cisco SX550X-52 Firmware | <2.5.0.90 | |
Cisco SX550X-52 | ||
Cisco SG550X-24 Firmware | <2.5.0.90 | |
Cisco SG550X-24 Firmware | ||
Cisco SG550X-24P Firmware | <2.5.0.90 | |
Cisco SG550X-24P Firmware | ||
Cisco SG550X-24MP Firmware | <2.5.0.90 | |
Cisco SG550X-24MP | ||
Cisco SG550X-24MPP Firmware | <2.5.0.90 | |
Cisco SG550X-24MPP | ||
Cisco SG550X-48MP Firmware | <2.5.0.90 | |
Cisco SG550X-48T | ||
Cisco SG550X-48P Firmware | <2.5.0.90 | |
Cisco SG550X-48P | ||
Cisco SG550X-48MP Firmware | <2.5.0.90 | |
Cisco SG550X-48MP | ||
Cisco SF550X-24 Firmware | <2.5.0.90 | |
Cisco SF550X-24 Firmware | ||
Cisco SF550X-24P Firmware | <2.5.0.90 | |
Cisco SF550X-24P | ||
Cisco SF550X-24MP Firmware | <2.5.0.90 | |
Cisco SF550X-24MP | ||
Cisco SF550X-48 Firmware | <2.5.0.90 | |
Cisco SF550X-48 | ||
Cisco SF550X-48P Firmware | <2.5.0.90 | |
Cisco SG550X-48P | ||
Cisco SG550X-48MP Firmware | <2.5.0.90 | |
Cisco SF550X-48MP | ||
Cisco SF200-24 Firmware | <1.4.11 | |
Cisco SF200-24P | ||
Cisco SF200-24FP Firmware | <1.4.11 | |
Cisco SF200-24FP | ||
Cisco SF200-24P Firmware | <1.4.11 | |
Cisco SF200-24P | ||
Cisco SF200-48 Firmware | <1.4.11 | |
Cisco SF200-48 Firmware | ||
Cisco SF200-48P Firmware | <1.4.11 | |
Cisco SF200-48P Firmware | ||
Cisco SF200E-24 Firmware | <1.4.11 | |
Cisco SF200E-24 Firmware | ||
Cisco SF200E-24 Firmware | <1.4.11 | |
Cisco SF200E-24 Firmware | ||
Cisco SF200E-48 Firmware | <1.4.11 | |
Cisco SF200E-48 | ||
Cisco SF200E-48P Firmware | <1.4.11 | |
Cisco SF200E-48P Firmware | ||
Cisco SG200-08 Firmware | <1.4.11 | |
Cisco SG200-08 Firmware | ||
Cisco SG200-08P Firmware | <1.4.11 | |
Cisco SG200-08P | ||
Cisco SG200-10FP Firmware | <1.4.11 | |
Cisco SG200-10FP Firmware | ||
Cisco SG200-18 Firmware | <1.4.11 | |
Cisco SG200-18 Firmware | ||
Cisco SG200-26FP Firmware | <1.4.11 | |
Cisco SG200-26P Firmware | ||
Cisco SG200-26FP Firmware | <1.4.11 | |
Cisco SG200-26FP Firmware | ||
Cisco SG200-26P Firmware | <1.4.11 | |
Cisco SG200-26P Firmware | ||
Cisco SG200-50P Firmware | <1.4.11 | |
Cisco SG200-50FP | ||
Cisco SG200-50FP Firmware | <1.4.11 | |
Cisco SG200-50FP | ||
Cisco SG200-50P Firmware | <1.4.11 | |
Cisco SG200-50P Firmware | ||
Cisco SF302-08PP Firmware | <1.4.11 | |
Cisco SF302-08PP Firmware | ||
Cisco SF302-08MPP Firmware | <1.4.11 | |
Cisco SF302-08MPP | ||
Cisco SG300-10PP Firmware | <1.4.11 | |
Cisco SG300-10PP Firmware | ||
Cisco SG300-10MPP Firmware | <1.4.11 | |
Cisco SG300-10MPP Firmware | ||
Cisco SF300-24PP Firmware | <1.4.11 | |
Cisco SF300-24PP | ||
Cisco SF300-48PP Firmware | <1.4.11 | |
Cisco SF300-48PP Firmware | ||
Cisco SG300-28PP Firmware | <1.4.11 | |
Cisco SG300-28PP | ||
Cisco SF300-08 Firmware | <1.4.11 | |
Cisco SF300-08 Firmware | ||
Cisco SF300-48P Firmware | <1.4.11 | |
Cisco SF300-48P Firmware | ||
Cisco SG300-10MP Firmware | <1.4.11 | |
Cisco SG300-10MP Firmware | ||
Cisco SG300-10P Firmware | <1.4.11 | |
Cisco SG300-10P | ||
Cisco SG300-10 Firmware | <1.4.11 | |
Cisco SG300-10 | ||
Cisco SG300-28P Firmware | <1.4.11 | |
Cisco SG300-28P | ||
Cisco SF300-24P | <1.4.11 | |
Cisco SF300-24P | ||
Cisco SF302-08MP Firmware | <1.4.11 | |
Cisco SF302-08MP | ||
Cisco SG300-28 Firmware | <1.4.11 | |
Cisco SG300-28 | ||
Cisco SF300-48P Firmware | <1.4.11 | |
Cisco SF300-48 | ||
Cisco SG300-20 Firmware | <1.4.11 | |
Cisco SG300-20 Firmware | ||
Cisco SF302-08P Firmware | <1.4.11 | |
Cisco SF302-08P Firmware | ||
Cisco SG300-52 Firmware | <1.4.11 | |
Cisco SG300-52 | ||
Cisco SF300-24P Firmware | <1.4.11 | |
Cisco SF300-24 | ||
Cisco SF302-08 Firmware | <1.4.11 | |
Cisco SF302-08 | ||
Cisco sf300-24mp firmware | <1.4.11 | |
Cisco SF300-24MP | ||
Cisco SG300-10SFP Firmware | <1.4.11 | |
Cisco SG300-10SFP Firmware | ||
Cisco SG300-28MP | <1.4.11 | |
Cisco SG300-28MP | ||
Cisco SG300-52P Firmware | <1.4.11 | |
Cisco SG300-52P | ||
Cisco SG300-52MP Firmware | <1.4.11 | |
Cisco SG300-52MP | ||
Cisco SG500-28PP Firmware | <1.4.11 | |
Cisco SG500-28MPP Firmware | ||
Cisco SG500-52MP | <1.4.11 | |
Cisco SG500-52 | ||
Cisco SG500XG-8F8T Firmware | <1.4.11 | |
Cisco SG500XG-8F8T Firmware | ||
Cisco SF500-24 | <1.4.11 | |
Cisco SF500-24MP | ||
Cisco SF500-24P | <1.4.11 | |
Cisco SF500-24P Firmware | ||
Cisco SF500-48P Firmware | <1.4.11 | |
Cisco SF500-48 Firmware | ||
Cisco SF500-48P Firmware | <1.4.11 | |
Cisco SF500-48 Firmware | ||
Cisco SG500-28 | <1.4.11 | |
Cisco SG500-28PP Firmware | ||
Cisco SG500-28P | <1.4.11 | |
Cisco SG500-28P | ||
Cisco SG500-52P | <1.4.11 | |
Cisco SG500-52 Firmware | ||
Cisco SG500-52P | <1.4.11 | |
Cisco SG500-52P | ||
Cisco SG500X-24 | <1.4.11 | |
Cisco SG500X-24P | ||
Cisco SG500X-24P | <1.4.11 | |
Cisco SG500X-24P | ||
Cisco SG500X-48 | <1.4.11 | |
Cisco SG500X-48MP Firmware | ||
Cisco SG500X-48P | <1.4.11 | |
Cisco SG500X-48P |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12718 has a medium severity rating, allowing unauthenticated remote attackers to perform cross-site scripting attacks.
To fix CVE-2019-12718, upgrade Cisco Small Business Smart and Managed Switches firmware to the latest version beyond 2.5.0.90.
CVE-2019-12718 affects several models including Cisco SF250, SF350, SG200, SG300, and older firmware versions of these switches.
Yes, CVE-2019-12718 can be exploited remotely by an unauthenticated attacker via the web-based interface.
CVE-2019-12718 facilitates cross-site scripting (XSS) attacks, which could be used to execute malicious scripts in the user's browser.