CVE-2019-1913 describes multiple critical vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches. These flaws, stemming from insufficient input validation and improper boundary checks, allow an unauthenticated, remote attacker to trigger a buffer overflow. Successful exploitation can lead to arbitrary code execution with root privileges on the affected device. The vulnerability carries a CVSS score of 9.8 (Critical), indicating a high-impact threat with a network-based attack vector and low attack complexity. An attacker can achieve complete compromise of confidentiality, integrity, and availability. While not listed on the CISA KEV catalog, public exploit code (EDB-47442) is available, and the vulnerability has garnered significant community attention and media coverage, including articles from BleepingComputer and SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.4.4CPE matchmatch criteria | cpe:2.3:o:cisco:sf-220-24_firmware:*:*:*:*:*:*:*:* | ||
< 1.1.4.4CPE matchmatch criteria | cpe:2.3:o:cisco:sf220-24p_firmware:*:*:*:*:*:*:*:* | ||
< 1.1.4.4CPE matchmatch criteria | cpe:2.3:o:cisco:sf220-48_firmware:*:*:*:*:*:*:*:* | ||
< 1.1.4.4CPE matchmatch criteria | cpe:2.3:o:cisco:sf220-48p_firmware:*:*:*:*:*:*:*:* | ||
< 1.1.4.4CPE matchmatch criteria | cpe:2.3:o:cisco:sg220-26_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.