{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-24T03:26:40.887","vulnerabilities":[{"cve":{"id":"CVE-2019-1913","sourceIdentifier":"psirt@cisco.com","published":"2019-08-07T06:15:11.933","lastModified":"2024-11-21T04:37:40.477","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating system. The vulnerabilities are due to insufficient validation of user-supplied input and improper boundary checks when reading data into an internal buffer. An attacker could exploit these vulnerabilities by sending malicious requests to the web management interface of an affected device. Depending on the configuration of the affected switch, the malicious requests must be sent via HTTP or HTTPS."},{"lang":"es","value":"Múltiples vulnerabilidades en la interfaz de administración web de los Switches Small Business 220 Series Smart de Cisco, podrían permitir que un atacante remoto no autenticado desbordar un búfer, que luego permite la ejecución de código arbitrario con privilegios root en el sistema operativo subyacente. Las vulnerabilidades son debido a una comprobación insuficiente de la entrada suministrada por el usuario y a controles de límites inapropiados cuando se leen datos en un búfer interno. Un atacante podría explotar estas vulnerabilidades enviando peticiones maliciosas a la interfaz de administración web de un dispositivo afectado. Dependiendo de la configuración del switch afectado, las peticiones maliciosas deben enviarse por medio de HTTP o HTTPS."}],"metrics":{"cvssMetricV30":[{"source":"psirt@cisco.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"psirt@cisco.com","type":"Secondary","description":[{"lang":"en","value":"CWE-119"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-119"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:sf-220-24_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.4.4","matchCriteriaId":"172DA894-0F90-4DC5-8A24-6184FBF4867F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:sf-220-24:-:*:*:*:*:*:*:*","matchCriteriaId":"727ED808-5B61-4379-8FC0-D3EFB4AEBC48"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:sf220-24p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.4.4","matchCriteriaId":"78CE146A-5B76-42B1-A508-C4D0648D0F00"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:sf220-24p:-:*:*:*:*:*:*:*","matchCriteriaId":"02258A44-A9BA-471B-AEEC-BDCBD44D6BD0"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:sf220-48_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.4.4","matchCriteriaId":"C11A7970-8195-45DC-B06F-389B78694FA5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:sf220-48:-:*:*:*:*:*:*:*","matchCriteriaId":"AC0EB976-563C-41B9-9F3F-2584721EDAA7"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:sf220-48p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.4.4","matchCriteriaId":"34FB9812-BA85-4AAF-9DAF-9981237B2419"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:sf220-48p:-:*:*:*:*:*:*:*","matchCriteriaId":"AAA7BE42-9570-4550-991A-4B6821D8F723"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:sg220-26_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.4.4","matchCriteriaId":"F4AE5C4A-761A-4C14-8603-5736273E3E4F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:sg220-26:-:*:*:*:*:*:*:*","matchCriteriaId":"69CE90A1-9914-457B-9E23-E63765275D62"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:sg220-26p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.4.4","matchCriteriaId":"AFADDDC4-932F-4921-A95E-7FBCB6D0E2A9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:sg220-26p:-:*:*:*:*:*:*:*","matchCriteriaId":"F70FBA10-934C-45F6-A01D-4BAD5F421C96"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:sg220-28_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.4.4","matchCriteriaId":"270F99AC-BAFC-4AE4-8B37-041036E55569"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:sg220-28:-:*:*:*:*:*:*:*","matchCriteriaId":"80A37E7F-E8C1-4B47-828A-A35E37D88EC0"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:sg220-28mp_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.4.4","matchCriteriaId":"E4B8DD39-B0FA-4A9C-B5A9-9B699C2ECE5F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:sg220-28mp:-:*:*:*:*:*:*:*","matchCriteriaId":"67CDEE3C-5A58-45A4-B092-07CA9418131F"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:sg220-50_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.4.4","matchCriteriaId":"6D64F75A-B865-4601-A5CB-52B5B4D1EEAB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:sg220-50:-:*:*:*:*:*:*:*","matchCriteriaId":"E024644E-83BD-49CA-8E27-8977B15713BE"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:sg220-50p_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.4.4","matchCriteriaId":"08588A15-5465-4219-8CBC-A53E9587BD62"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:sg220-50p:-:*:*:*:*:*:*:*","matchCriteriaId":"808746E3-4A3D-44F3-8510-52D699F7D3C2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:sg220-52_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.4.4","matchCriteriaId":"18FDB744-9725-440E-A123-69496067EDBF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:cisco:sg220-52:-:*:*:*:*:*:*:*","matchCriteriaId":"9C831CAB-9A14-437D-AF6C-A3C81B2CD67A"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/154667/Realtek-Managed-Switch-Controller-RTL83xx-Stack-Overflow.html","source":"psirt@cisco.com"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-rce","source":"psirt@cisco.com","tags":["Vendor Advisory"]},{"url":"http://packetstormsecurity.com/files/154667/Realtek-Managed-Switch-Controller-RTL83xx-Stack-Overflow.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-rce","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}