CVE-2019-1859 is a vulnerability in Cisco Small Business Switches that allows an attacker to bypass client-side certificate authentication in the SSH process, reverting to password authentication. This high-severity vulnerability (CVSS 7.2) has a low attack complexity and could lead to full administrative access if default credentials are not changed. There are no known public exploits, Metasploit modules, or significant community discussion, indicating a low current exploitation risk. While no workarounds exist, disabling client-side certificate authentication and using strong passwords is recommended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.10.6CPE matchmatch criteria | cpe:2.3:o:cisco:sg200-50_firmware:*:*:*:*:*:*:*:* | ||
< 1.4.10.6CPE matchmatch criteria | cpe:2.3:o:cisco:sg200-50p_firmware:*:*:*:*:*:*:*:* | ||
< 1.4.10.6CPE matchmatch criteria | cpe:2.3:o:cisco:sg200-50fp_firmware:*:*:*:*:*:*:*:* | ||
< 1.4.10.6CPE matchmatch criteria | cpe:2.3:o:cisco:sg200-26_firmware:*:*:*:*:*:*:*:* | ||
< 1.4.10.6CPE matchmatch criteria | cpe:2.3:o:cisco:sg200-26p_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco Small Business Switch Security Feature Bypass
May 1, 2019Cisco Small Business Switch Security Feature Bypass
May 1, 2019Cisco Small Business Switch Security Feature Bypass
May 1, 2019Cisco Small Business Switch Security Feature Bypass
May 1, 2019Cisco Small Business Switch Security Feature Bypass
May 1, 2019Cisco Small Business Switch Security Feature Bypass
May 1, 2019