vendor:
Small Business 200, 300, 500 Series Managed Switches
by:
Ramikan
6.1
CVSS
MEDIUM
Information Gathering & Open Redirect due to host header
601
CWE
Product Name: Small Business 200, 300, 500 Series Managed Switches
Affected Version From: 1.3.7.18
Affected Version To: 1.3.7.18
Patch Exists: YES
Related CWE: CVE-2019-1943
CPE: h:cisco:small_business_300_series_managed_switches
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Cisco C300 Switch
2019
CISCO Small Business 200, 300, 500 Switches Multiple Vulnerabilities
Unauthenticated user can find the version number and device type by visiting this link directly. Can change to different domain under the host header and redirect the request to fake website and can be used for phishing attack also can be used for domain fronting.
Mitigation:
Disable the web management interface, if not required. Use strong authentication and authorization mechanisms.