A vulnerability in the GUI function in the web framework code of Cisco Small Business SG300 Managed Switches could allow an unauthenticated, remote attacker to cause the HTTPS process to become unresponsive, resulting in a partial denial of service (DoS) condition.
 
The vulnerability is due to improper handling, processing, and termination of HTTPS connections. An attacker could exploit this vulnerability by sending crafted HTTPS requests to management-enabled interfaces of an affected system.

Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160127-sbms

Leave a Reply