A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by convincing a user to follow a malicious link or by intercepting a user request and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information. This vulnerability affects the following Cisco Small Business 300 and 500 Series Managed Switches: Cisco 350 Series Managed Switches, Cisco 350X Series Stackable Managed Switches, Cisco 550X Series Stackable Managed Switches, Cisco ESW2 Series Advanced Switches, Cisco Small Business 300 Series Managed Switches, Cisco Small Business 500 Series Stackable Managed Switches. Cisco Bug IDs: CSCvg29980.

Project Subscriptions

Vendors Products
Esw2-350g-52 Subscribe
Esw2-350g-52 Firmware Subscribe
Esw2-350g-52dc Subscribe
Esw2-350g-52dc Firmware Subscribe
Esw2-550x-48 Subscribe
Esw2-550x-48 Firmware Subscribe
Esw2-550x-48dc Subscribe
Esw2-550x-48dc Firmware Subscribe
Sf300-08 Subscribe
Sf300-08 Firmware Subscribe
Sf300-24 Subscribe
Sf300-24 Firmware Subscribe
Sf300-24mp Subscribe
Sf300-24mp Firmware Subscribe
Sf300-24p Subscribe
Sf300-24p Firmware Subscribe
Sf300-24pp Subscribe
Sf300-24pp Firmware Subscribe
Sf300-48 Subscribe
Sf300-48 Firmware Subscribe
Sf300-48p Subscribe
Sf300-48p Firmware Subscribe
Sf300-48pp Subscribe
Sf300-48pp Firmware Subscribe
Sf302-08 Subscribe
Sf302-08 Firmware Subscribe
Sf302-08mp Subscribe
Sf302-08mp Firmware Subscribe
Sf302-08mpp Subscribe
Sf302-08mpp Firmware Subscribe
Sf302-08p Subscribe
Sf302-08p Firmware Subscribe
Sf302-08pp Subscribe
Sf302-08pp Firmware Subscribe
Sf350-48 Subscribe
Sf350-48 Firmware Subscribe
Sf350-48mp Subscribe
Sf350-48mp Firmware Subscribe
Sf350-48p Subscribe
Sf350-48p Firmware Subscribe
Sf500-24 Subscribe
Sf500-24 Firmware Subscribe
Sf500-24p Subscribe
Sf500-24p Firmware Subscribe
Sf500-48 Subscribe
Sf500-48 Firmware Subscribe
Sf500-48p Subscribe
Sf500-48p Firmware Subscribe
Sf550x-24 Subscribe
Sf550x-24 Firmware Subscribe
Sf550x-24mp Subscribe
Sf550x-24mp Firmware Subscribe
Sf550x-24p Subscribe
Sf550x-24p Firmware Subscribe
Sf550x-48 Subscribe
Sf550x-48 Firmware Subscribe
Sf550x-48mp Subscribe
Sf550x-48mp Firmware Subscribe
Sf550x-48p Subscribe
Sf550x-48p Firmware Subscribe
Sg300-10 Subscribe
Sg300-10 Firmware Subscribe
Sg300-10mp Subscribe
Sg300-10mp Firmware Subscribe
Sg300-10mpp Subscribe
Sg300-10mpp Firmware Subscribe
Sg300-10p Subscribe
Sg300-10p Firmware Subscribe
Sg300-10pp Subscribe
Sg300-10pp Firmware Subscribe
Sg300-10sfp Subscribe
Sg300-10sfp Firmware Subscribe
Sg300-20 Subscribe
Sg300-20 Firmware Subscribe
Sg300-28 Subscribe
Sg300-28 Firmware Subscribe
Sg300-28mp Subscribe
Sg300-28mp Firmware Subscribe
Sg300-28p Subscribe
Sg300-28p Firmware Subscribe
Sg300-28pp Subscribe
Sg300-28pp Firmware Subscribe
Sg300-52 Subscribe
Sg300-52 Firmware Subscribe
Sg300-52mp Subscribe
Sg300-52mp Firmware Subscribe
Sg300-52p Subscribe
Sg300-52p Firmware Subscribe
Sg350-10 Subscribe
Sg350-10 Firmware Subscribe
Sg350-10mp Subscribe
Sg350-10mp Firmware Subscribe
Sg350-10p Subscribe
Sg350-10p Firmware Subscribe
Sg350-28 Subscribe
Sg350-28 Firmware Subscribe
Sg350-28mp Subscribe
Sg350-28mp Firmware Subscribe
Sg350-28p Subscribe
Sg350-28p Firmware Subscribe
Sg350x-24 Subscribe
Sg350x-24 Firmware Subscribe
Sg350x-24mp Subscribe
Sg350x-24mp Firmware Subscribe
Sg350x-24p Subscribe
Sg350x-24p Firmware Subscribe
Sg350x-48 Subscribe
Sg350x-48 Firmware Subscribe
Sg350x-48mp Subscribe
Sg350x-48mp Firmware Subscribe
Sg350x-48p Subscribe
Sg350x-48p Firmware Subscribe
Sg350xg-24f Subscribe
Sg350xg-24f Firmware Subscribe
Sg350xg-24t Subscribe
Sg350xg-24t Firmware Subscribe
Sg350xg-2f10 Subscribe
Sg350xg-2f10 Firmware Subscribe
Sg350xg-48t Subscribe
Sg350xg-48t Firmware Subscribe
Sg355-10p Subscribe
Sg355-10p Firmware Subscribe
Sg500-28 Subscribe
Sg500-28 Firmware Subscribe
Sg500-28mpp Subscribe
Sg500-28mpp Firmware Subscribe
Sg500-28p Subscribe
Sg500-28p Firmware Subscribe
Sg500-52 Subscribe
Sg500-52 Firmware Subscribe
Sg500-52mp Subscribe
Sg500-52mp Firmware Subscribe
Sg500-52p Subscribe
Sg500-52p Firmware Subscribe
Sg500x-24 Subscribe
Sg500x-24 Firmware Subscribe
Sg500x-24p Subscribe
Sg500x-24p Firmware Subscribe
Sg500x-48 Subscribe
Sg500x-48 Firmware Subscribe
Sg500x-48p Subscribe
Sg500x-48p Firmware Subscribe
Sg500xg-8f8t Subscribe
Sg500xg-8f8t Firmware Subscribe
Sg550x-24 Subscribe
Sg550x-24 Firmware Subscribe
Sg550x-24mp Subscribe
Sg550x-24mp Firmware Subscribe
Sg550x-24mpp Subscribe
Sg550x-24mpp Firmware Subscribe
Sg550x-24p Subscribe
Sg550x-24p Firmware Subscribe
Sg550x-48 Subscribe
Sg550x-48 Firmware Subscribe
Sg550x-48mp Subscribe
Sg550x-48mp Firmware Subscribe
Sg550x-48p Subscribe
Sg550x-48p Firmware Subscribe
Sx550x-12f Subscribe
Sx550x-12f Firmware Subscribe
Sx550x-16ft Subscribe
Sx550x-16ft Firmware Subscribe
Sx550x-24 Subscribe
Sx550x-24 Firmware Subscribe
Sx550x-24f Subscribe
Sx550x-24f Firmware Subscribe
Sx550x-24ft Subscribe
Sx550x-24ft Firmware Subscribe
Sx550x-52 Subscribe
Sx550x-52 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2017-3881 A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by convincing a user to follow a malicious link or by intercepting a user request and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information. This vulnerability affects the following Cisco Small Business 300 and 500 Series Managed Switches: Cisco 350 Series Managed Switches, Cisco 350X Series Stackable Managed Switches, Cisco 550X Series Stackable Managed Switches, Cisco ESW2 Series Advanced Switches, Cisco Small Business 300 Series Managed Switches, Cisco Small Business 500 Series Stackable Managed Switches. Cisco Bug IDs: CSCvg29980.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 02 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-12-02T21:46:39.725Z

Reserved: 2017-08-03T00:00:00.000Z

Link: CVE-2017-12308

cve-icon Vulnrichment

Updated: 2024-08-05T18:36:55.894Z

cve-icon NVD

Status : Modified

Published: 2018-01-18T06:29:00.267

Modified: 2024-11-21T03:09:16.797

Link: CVE-2017-12308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses