cisco-sa-20190501-scbv: Cisco Small Business Switches Secure Shell Certificate Authentication Bypass Vulnerability
A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow an attacker to bypass client-side certificate authentication and revert to password authentication.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-scbv
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20190501-scbv?
The severity of cisco-sa-20190501-scbv is considered high as it allows attackers to bypass client-side certificate authentication.
How do I fix cisco-sa-20190501-scbv?
To fix cisco-sa-20190501-scbv, update your Cisco Small Business Switches software to the latest version provided by Cisco.
Which products are affected by cisco-sa-20190501-scbv?
cisco-sa-20190501-scbv affects Cisco 250, 350, 350X, 550X Series and Small Business 200, 300, and 500 Series switches.
What is the impact of cisco-sa-20190501-scbv?
The impact of cisco-sa-20190501-scbv is that it allows unauthorized access through compromised SSH authentication mechanisms.
When was cisco-sa-20190501-scbv disclosed?
cisco-sa-20190501-scbv was disclosed on May 1, 2019.