CVE detail

CVE-2019-1806 — CVE-2019-1806

Published 2019-05-15 · Modified 2026-06-17 · Vendor cisco · Product sf200-24_firmware · Source nvd
HIGH
severity
CVSS-derived band
7.7
CVSS v3
0–10 scale
0.0208
EPSS probability
exploitation probability, 30d
80.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches could allow an authenticated, remote attacker to cause the SNMP application of an affected device to cease processing traffic, resulting in the CPU utilization reaching one hundred percent. Manual intervention may be required before a device resumes normal operations. The vulnerability is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could exploit this vulnerability by sending a malicious SNMP packet to an affected device. A successful exploit could allow the attacker to cause the device to cease forwarding traffic, which could resu

Remediation

ProductVulnerable rangeFixed versionAdvisory
Cisco Cisco 550X Series Stackable Managed Switches>=unspecified<1.4.10.61.4.10.6advisory ↗
Cisco Cisco 550X Series Stackable Managed Switches>=unspecified<2.5.0.782.5.0.78advisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.