CVE-2019-15993

MEDIUM

Cisco Small Business Switches - Info Disclosure

Title source: llm

Description

A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files.

Exploits (1)

exploitdb WORKING POC
pythonremotehardware
https://www.exploit-db.com/exploits/51248

Scores

CVSS v3 5.3
EPSS 0.1234
EPSS Percentile 93.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-16 CWE-287
Status published
Products (50)
cisco/sf200-24_firmware < 1.4.11.4
cisco/sf200-24fp_firmware < 1.4.11.4
cisco/sf200-24p_firmware < 1.4.11.4
cisco/sf200-48_firmware < 1.4.11.4
cisco/sf200-48p_firmware < 1.4.11.4
cisco/sf250-24_firmware < 2.5.0.92
cisco/sf250-24p_firmware < 2.5.0.92
cisco/sf250-48_firmware < 2.5.0.92
cisco/sf250-48hp_firmware < 2.5.0.92
cisco/sf300-08_firmware < 1.4.11.4
... and 40 more
Published Sep 23, 2020
Tracked Since Feb 18, 2026