cisco-sa-20200129-smlbus-switch-disclos: Cisco Small Business Switches Information Disclosure Vulnerability
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200129-smlbus-switch-disclos
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20200129-smlbus-switch-disclos?
The severity of cisco-sa-20200129-smlbus-switch-disclos is classified as high due to the potential for sensitive information exposure.
How do I fix cisco-sa-20200129-smlbus-switch-disclos?
To fix cisco-sa-20200129-smlbus-switch-disclos, apply the recommended software updates provided by Cisco for Small Business Switches.
Who is affected by cisco-sa-20200129-smlbus-switch-disclos?
Cisco Small Business Switches are affected by cisco-sa-20200129-smlbus-switch-disclos due to the lack of proper authentication controls.
What kind of information can be accessed due to cisco-sa-20200129-smlbus-switch-disclos?
An unauthenticated remote attacker could access sensitive device information through the web UI due to cisco-sa-20200129-smlbus-switch-disclos.
Is cisco-sa-20200129-smlbus-switch-disclos easily exploitable?
Yes, cisco-sa-20200129-smlbus-switch-disclos is easily exploitable as it does not require authentication for access.