Certain Cisco Small Business Series Switches are affected by multiple vulnerabilities in their web-based user interface. This comes on the heels of the recent Cisco Phone Adapter vulnerabilities earlier this month.These vulnerabilities have the potential to enable an unauthorized remote attacker to induce a denial of service (DoS) situation or execute arbitrary code with root privileges on a targeted device. The root cause of these vulnerabilities lies in the inadequate validation of requests sent to the web interface.

The vulnerabilities impact specific models of Cisco Small Business Switches, provided they are operating on a firmware version that is susceptible to these vulnerabilities. The affected switch models include:
- 250 Series Smart Switches
- 350 Series Managed Switches
- 350X Series Stackable Managed Switches
- 550X Series Stackable Managed Switches
- Business 250 Series Smart Switches
- Business 350 Series Managed Switches
- Small Business 200 Series Smart Switches
- Small Business 300 Series Managed Switches
- Small Business 500 Series Stackable Managed Switches
The vulnerabilities in question are independent of each other, meaning that exploiting one vulnerability does not require exploiting another. Furthermore, it is possible for a software release to be affected by one vulnerability without being affected by the others.
Here are the details regarding the vulnerabilities:
CVE-2023-20159: Cisco Small Business Series Switches Stack Buffer Overflow Vulnerability
There is a vulnerability in the web-based user interface of Cisco Small Business Series Switches, which could potentially allow an unauthorized remote attacker to execute arbitrary code on a compromised device.
This vulnerability is a result of inadequate validation of requests sent to the web interface. To exploit this vulnerability, an attacker can send a specifically crafted request via the web-based user interface. If successful, this exploit would grant the attacker the ability to execute arbitrary code with root privileges on the affected device.
Cisco has addressed this vulnerability by releasing software updates. Unfortunately, there are no workarounds available to mitigate this vulnerability.
Bug ID(s): CSCwe27425, CSCwe32323
CVE ID: CVE-2023-20159
Security Impact Rating (SIR): Critical
CVSS Base Score: 9.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2023-20160: Cisco Small Business Series Switches Unauthenticated BSS Buffer Overflow Vulnerability
An unauthenticated, remote attacker could potentially execute arbitrary code on an affected device through a vulnerability found in the web-based user interface of Cisco Small Business Series Switches.
The root cause of this vulnerability lies in the insufficient validation of requests sent to the web interface. By crafting a specific request through the web-based user interface, an attacker can exploit this vulnerability. If successful, the attacker would gain the ability to execute arbitrary code with root privileges on the compromised device.
To mitigate this vulnerability, Cisco has released software updates that address the issue. Unfortunately, there are no workarounds available to resolve this vulnerability.
Bug ID(s): CSCwe27441, CSCwe32326
CVE ID: CVE-2023-20160
Security Impact Rating (SIR): Critical
CVSS Base Score: 9.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2023-20161: Cisco Small Business Series Switches Unauthenticated Stack Buffer Overflow Vulnerability
An unauthorized remote attacker, without authentication, could potentially execute arbitrary code on an impacted device by exploiting a vulnerability in the web-based user interface of Cisco Small Business Series Switches.
The vulnerability is a result of inadequate validation of requests sent to the web interface. By manipulating a specially crafted request via the web-based user interface, an attacker can take advantage of this vulnerability. If the exploit is successful, the attacker would gain the ability to execute arbitrary code with root privileges on the affected device.
To address this vulnerability, Cisco has released software updates that rectify the issue. Unfortunately, there are no workarounds available to mitigate this vulnerability.
Bug ID(s): CSCwe27444, CSCwe32334
CVE ID: CVE-2023-20161
Security Impact Rating (SIR): Critical
CVSS Base Score: 9.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2023-20189: Cisco Small Business Series Switches Unauthenticated Stack Buffer Overflow Vulnerability
The web-based user interface of Cisco Small Business Series Switches contains a vulnerability that could be exploited by an unauthenticated remote attacker. This vulnerability arises from inadequate validation of requests transmitted to the web interface. To exploit this vulnerability, an attacker can send a specifically crafted request through the web-based user interface. If the exploit is successful, it would grant the attacker the ability to execute arbitrary code on the affected device, with root privileges.
Cisco has responded to this vulnerability by releasing software updates that resolve the issue. Unfortunately, there are no alternative measures or workarounds available to address this vulnerability.
Bug ID(s): CSCwe27424, CSCwe32321
CVE ID: CVE-2023-20189
Security Impact Rating (SIR): Critical
CVSS Base Score: 9.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2023-20024: Cisco Small Business Series Switches Unauthenticated Heap Buffer Overflow Vulnerability
The web-based user interface of Cisco Small Business Series Switches contains a vulnerability that could be exploited by an unauthenticated remote attacker to trigger a denial of service (DoS) situation on a targeted device.
This vulnerability stems from inadequate validation of requests transmitted to the web interface. By sending a specially crafted request through the web-based user interface, an attacker can exploit this vulnerability. A successful exploit would enable the attacker to initiate a DoS condition on the affected device.
Cisco has responded to this vulnerability by releasing software updates that resolve the issue. Unfortunately, there are no alternative measures or workarounds available to address this vulnerability.
Bug ID(s): CSCwe27386, CSCwe32312
CVE ID: CVE-2023-20024
Security Impact Rating (SIR): High
CVSS Base Score: 8.6
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVE-2023-20156: Cisco Small Business Series Switches Unauthenticated Heap Buffer Overflow Vulnerability
An unauthenticated remote attacker has the potential to induce a denial of service (DoS) situation on an affected device by exploiting a vulnerability in the web-based user interface of Cisco Small Business Series Switches.
The root cause of this vulnerability lies in the inadequate validation of requests sent to the web interface. By sending a carefully crafted request through the web-based user interface, an attacker can leverage this vulnerability. If the exploit is successful, it can result in a DoS condition on the affected device.
To mitigate this vulnerability, Cisco has issued software updates that rectify the issue. Unfortunately, there are no known workarounds available to address this vulnerability.
Bug ID(s): CSCwe27393, CSCwe32313
CVE ID: CVE-2023-20156
Security Impact Rating (SIR): High
CVSS Base Score: 8.6
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVE-2023-20157: Cisco Small Business Series Switches Unauthenticated Heap Buffer Overflow Vulnerability
An unauthenticated remote attacker has the potential to trigger a denial of service (DoS) situation on an affected device by exploiting a vulnerability found in the web-based user interface of Cisco Small Business Series Switches.
This vulnerability arises from inadequate validation of requests sent to the web interface. By sending a carefully crafted request through the web-based user interface, an attacker can exploit this vulnerability. Successful exploitation can result in causing a DoS condition on the affected device.
To mitigate this vulnerability, Cisco has provided software updates that resolve the issue. Unfortunately, there are no known workarounds available to mitigate this vulnerability.
Bug ID(s): CSCwe27394, CSCwe32315
CVE ID: CVE-2023-20157
Security Impact Rating (SIR): High
CVSS Base Score: 8.6
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVE-2023-20158: Cisco Small Business Series Switches Unauthenticated Denial-of-Service Vulnerability
An unauthenticated remote attacker has the potential to trigger a denial of service (DoS) situation on an affected device by exploiting a vulnerability found in the web-based user interface of Cisco Small Business Series Switches.
This vulnerability arises from inadequate validation of requests sent to the web interface. By sending a carefully crafted request through the web-based user interface, an attacker can exploit this vulnerability. Successful exploitation can result in causing a DoS condition on the affected device.
To mitigate this vulnerability, Cisco has provided software updates that resolve the issue. Unfortunately, there are no known workarounds available to mitigate this vulnerability.
Bug ID(s): CSCwe27403, CSCwe32318
CVE ID: CVE-2023-20158
Security Impact Rating (SIR): High
CVSS Base Score: 8.6
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVE-2023-20162: Cisco Small Business Series Switches Unauthenticated Configuration Reading Vulnerability
A vulnerability in the web-based user interface of Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to read unauthorized information on an affected device.
This vulnerability is due to improper validation of requests that are sent to the web interface. An attacker could exploit this vulnerability by sending a crafted request through the web-based interface. A successful exploit could allow the attacker to read unauthorized information on an affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Bug ID(s): CSCwe27445, CSCwe32338
CVE ID: CVE-2023-20162
Security Impact Rating (SIR): High
CVSS Base Score: 7.5
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What to do?
Cisco has made available software updates that are provided free of charge to address the vulnerabilities mentioned in this advisory. Customers who have service contracts granting them access to regular software updates should acquire the security fixes through their usual update channels.
Cisco customers are encouraged to work with Cisco Support and/or their local Cisco resellers to apply fixes.
For more details on these vulnerabilities, visit Cisco’s official page: Cisco Small Business Series Switches Buffer Overflow Vulnerabilities