CVE-2023-20024

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
ciscobusiness_250-16p-2g_firmware
-
ciscobusiness_250-16t-2g_firmware
-
ciscobusiness_250-24fp-4g_firmware
-
ciscobusiness_250-24fp-4x_firmware
-
ciscobusiness_250-24p-4g_firmware
-
ciscobusiness_250-24p-4x_firmware
-
ciscobusiness_250-24pp-4g_firmware
-
ciscobusiness_250-24t-4g_firmware
-
ciscobusiness_250-24t-4x_firmware
-
ciscobusiness_250-48p-4g_firmware
-
ciscobusiness_250-48p-4x_firmware
-
ciscobusiness_250-48pp-4g_firmware
-
ciscobusiness_250-48t-4g_firmware
-
ciscobusiness_250-48t-4x_firmware
-
ciscobusiness_250-8fp-e-2g_firmware
-
ciscobusiness_250-8p-e-2g_firmware
-
ciscobusiness_250-8pp-d_firmware
-
ciscobusiness_250-8pp-e-2g_firmware
-
ciscobusiness_250-8t-d_firmware
-
ciscobusiness_250-8t-e-2g_firmware
-
ciscobusiness_350-12np-4x_firmware
-
ciscobusiness_350-12xs_firmware
-
ciscobusiness_350-12xt_firmware
-
ciscobusiness_350-16fp-2g_firmware
-
ciscobusiness_350-16p-2g_firmware
-
ciscobusiness_350-16p-e-2g_firmware
-
ciscobusiness_350-16t-2g_firmware
-
ciscobusiness_350-16t-e-2g_firmware
-
ciscobusiness_350-16xts_firmware
-
ciscobusiness_350-24fp-4g_firmware
-
ciscobusiness_350-24fp-4x_firmware
-
ciscobusiness_350-24mgp-4x_firmware
-
ciscobusiness_350-24ngp-4x_firmware
-
ciscobusiness_350-24p-4g_firmware
-
ciscobusiness_350-24p-4x_firmware
-
ciscobusiness_350-24s-4g_firmware
-
ciscobusiness_350-24t-4g_firmware
-
ciscobusiness_350-24t-4x_firmware
-
ciscobusiness_350-24xs_firmware
-
ciscobusiness_350-24xt_firmware
-
ciscobusiness_350-24xts_firmware
-
ciscobusiness_350-48fp-4g_firmware
-
ciscobusiness_350-48fp-4x_firmware
-
ciscobusiness_350-48ngp-4x_firmware
-
ciscobusiness_350-48p-4g_firmware
-
ciscobusiness_350-48p-4x_firmware
-
ciscobusiness_350-48t-4g_firmware
-
ciscobusiness_350-48t-4x_firmware
-
ciscobusiness_350-48xt-4x_firmware
-
ciscobusiness_350-8fp-2g_firmware
-
ciscobusiness_350-8fp-e-2g_firmware
-
ciscobusiness_350-8mgp-2x_firmware
-
ciscobusiness_350-8mp-2x_firmware
-
ciscobusiness_350-8p-2g_firmware
-
ciscobusiness_350-8p-e-2g_firmware
-
ciscobusiness_350-8s-e-2g_firmware
-
ciscobusiness_350-8t-e-2g_firmware
-
ciscobusiness_350-8xt_firmware
-
ciscosf200-24_firmware
-
ciscosf200-24fp_firmware
-
ciscosf200-24p_firmware
-
ciscosf200-48_firmware
-
ciscosf200-48p_firmware
-
ciscosf200e-24_firmware
-
ciscosf200e-24p_firmware
-
ciscosf200e-48_firmware
-
ciscosf200e-48p_firmware
-
ciscosf200e48p_firmware
-
ciscosf250-08_firmware
-
ciscosf250-08hp_firmware
-
ciscosf250-10p_firmware
-
ciscosf250-18_firmware
-
ciscosf250-24_firmware
-
ciscosf250-24p_firmware
-
ciscosf250-26_firmware
-
ciscosf250-26hp_firmware
-
ciscosf250-26p_firmware
-
ciscosf250-48_firmware
-
ciscosf250-48hp_firmware
-
ciscosf250-50_firmware
-
ciscosf250-50hp_firmware
-
ciscosf250-50p_firmware
-
ciscosf250x-24_firmware
-
ciscosf250x-24p_firmware
-
ciscosf250x-48_firmware
-
ciscosf250x-48p_firmware
-
ciscosf300-08_firmware
-
ciscosf300-24_firmware
-
ciscosf300-24mp_firmware
-
ciscosf300-24p_firmware
-
ciscosf300-24pp_firmware
-
ciscosf300-48_firmware
-
ciscosf300-48p_firmware
-
ciscosf300-48pp_firmware
-
ciscosf302-08_firmware
-
ciscosf302-08mpp_firmware
-
ciscosf302-08pp_firmware
-
ciscosf350-08_firmware
-
ciscosf350-10_firmware
-
ciscosf350-10mp_firmware
-
ciscosf350-10p_firmware
-
ciscosf350-10sfp_firmware
-
ciscosf350-20_firmware
-
ciscosf350-24_firmware
-
ciscosf350-24mp_firmware
-
ciscosf350-24p_firmware
-
ciscosf350-28_firmware
-
ciscosf350-28mp_firmware
-
ciscosf350-28p_firmware
-
ciscosf350-28sfp_firmware
-
ciscosf350-48_firmware
-
ciscosf350-48mp_firmware
-
ciscosf350-48p_firmware
-
ciscosf350-52_firmware
-
ciscosf350-52mp_firmware
-
ciscosf350-52p_firmware
-
ciscosf350-8mp_firmware
-
ciscosf350-8pd_firmware
-
ciscosf352-08_firmware
-
ciscosf352-08mp_firmware
-
ciscosf352-08p_firmware
-
ciscosf355-10p_firmware
-
ciscosf500-18p_firmware
-
ciscosf500-24_firmware
-
ciscosf500-24mp_firmware
-
ciscosf500-24p_firmware
-
ciscosf500-48_firmware
-
ciscosf500-48mp_firmware
-
ciscosf500-48p_firmware
-
ciscosf550x-24_firmware
-
ciscosf550x-24mp_firmware
-
ciscosf550x-24p_firmware
-
ciscosf550x-48_firmware
-
ciscosf550x-48mp_firmware
-
ciscosf550x-48p_firmware
-
ciscosg200-08_firmware
-
ciscosg200-08p_firmware
-
ciscosg200-10fp_firmware
-
ciscosg200-18_firmware
-
ciscosg200-26_firmware
-
ciscosg200-26fp_firmware
-
ciscosg200-26p_firmware
-
ciscosg200-50_firmware
-
ciscosg200-50fp_firmware
-
ciscosg200-50p_firmware
-
ciscosg250-08_firmware
-
ciscosg250-08hp_firmware
-
ciscosg250-10p_firmware
-
ciscosg250-18_firmware
-
ciscosg250-24_firmware
-
ciscosg250-24p_firmware
-
ciscosg250-26_firmware
-
ciscosg250-26hp_firmware
-
ciscosg250-26p_firmware
-
ciscosg250-48_firmware
-
ciscosg250-48hp_firmware
-
ciscosg250-50_firmware
-
ciscosg250-50hp_firmware
-
ciscosg250-50p_firmware
-
ciscosg250x-24_firmware
-
ciscosg250x-24p_firmware
-
ciscosg250x-48_firmware
-
ciscosg250x-48p_firmware
-
ciscosg300-10_firmware
-
ciscosg300-10mp_firmware
-
ciscosg300-10mpp_firmware
-
ciscosg300-10p_firmware
-
ciscosg300-10pp_firmware
-
ciscosg300-10sfp_firmware
-
ciscosg300-20_firmware
-
ciscosg300-28_firmware
-
ciscosg300-28mp_firmware
-
ciscosg300-28p_firmware
-
ciscosg300-28pp_firmware
-
ciscosg300-28sfp_firmware
-
ciscosg300-52_firmware
-
ciscosg300-52mp_firmware
-
ciscosg300-52p_firmware
-
ciscosg350-10_firmware
-
ciscosg350-10mp_firmware
-
ciscosg350-10p_firmware
-
ciscosg350-28_firmware
-
ciscosg350-28mp_firmware
-
ciscosg350-28p_firmware
-
ciscosg350x-12pmv_firmware
-
ciscosg350x-24_firmware
-
ciscosg350x-24mp_firmware
-
ciscosg350x-24p_firmware
-
ciscosg350x-24pd_firmware
-
ciscosg350x-24pv_firmware
-
ciscosg350x-48_firmware
-
ciscosg350x-48mp_firmware
-
ciscosg350x-48p_firmware
-
ciscosg350x-48pv_firmware
-
ciscosg350x-8pmd_firmware
-
ciscosg350xg-24f_firmware
-
ciscosg350xg-24t_firmware
-
ciscosg350xg-2f10_firmware
-
ciscosg350xg-48t_firmware
-
ciscosg355-10mp_firmware
-
ciscosg355-10p_firmware
-
ciscosg500-28_firmware
-
ciscosg500-28mpp_firmware
-
ciscosg500-28p_firmware
-
ciscosg500-28pp_firmware
-
ciscosg500-52p_firmware
-
ciscosg500-52pp_firmware
-
ciscosg500x-24_firmware
-
ciscosg500x-24mpp_firmware
-
ciscosg500x-24p_firmware
-
ciscosg500x-48_firmware
-
ciscosg500x-48mp_firmware
-
ciscosg500x-48mpp_firmware
-
ciscosg500x-48p_firmware
-
ciscosg500x24mpp_firmware
-
ciscosg500xg-8f8t_firmware
-
ciscosg500xg8f8t_firmware
-
ciscosg550x-24_firmware
-
ciscosg550x-24mp_firmware
-
ciscosg550x-24mpp_firmware
-
ciscosg550x-24p_firmware
-
ciscosg550x-48_firmware
-
ciscosg550x-48mp_firmware
-
ciscosg550x-48p_firmware
-
ciscosg550x-48t_firmware
-
ciscosg550xg-24f_firmware
-
ciscosg550xg-24t_firmware
-
ciscosg550xg-48t_firmware
-
ciscosg550xg-8f8t_firmware
-
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
cisco250_series_smart_switches_firmware
𝑥
< 2.5.9.16
ADP
cisco350_series_managed_switches_firmware
𝑥
< 2.5.9.16
ADP
cisco350x_series_stackable_managed_switches_firmware
𝑥
< 2.5.9.16
ADP
cisco550x_series_stackable_managed_switches_firmware
𝑥
< 2.5.9.16
ADP
ciscobusiness_250_series_smart_switches_firmware
𝑥
< 3.3.0.16
ADP
ciscobusiness_350_series_managed_switches_firmware
𝑥
< 3.3.0.16
ADP
ciscosmall_business_200_series_smart_switches_firmware
𝑥
< *
ADP
ciscosmall_business_300_series_managed_switches_firmware
𝑥
< *
ADP
ciscosmall_business_500_series_stackable_managed_switches_firmware
𝑥
< *
ADP