Cisco Small Business Series Switches Open Redirect Vulnerability
53Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 4.7epss 11%
from disclosure to weapon0 days
Published on NVDJul 17
1st PoCJul 15
exploitation probability
11%top 5% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting a user's HTTP request and modifying it into a request that causes the web interface to redirect the user to a specific malicious URL. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Cisco · Cisco Small Business 300 Series Managed Switchespublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/47118unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.