CVE-2023-20157 describes multiple critical vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches. These flaws, stemming from improper request validation, allow an unauthenticated, remote attacker to achieve a denial of service or execute arbitrary code with root privileges. With a CVSS score of 9.8 (Critical), the attack vector is network-based with low complexity, leading to high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), but it has garnered some community discussion and media coverage, indicating awareness of its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:business_250-16p-2g_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:business_250-16t-2g_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:business_250-24fp-4g_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:business_250-24fp-4x_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:business_250-24p-4g_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.