ID

VAR-201303-0399


CVE

CVE-2013-1154


TITLE

Cisco Small Business Switches Denial of Service Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2013-01689 // CNNVD: CNNVD-201303-137

DESCRIPTION

The Cisco Small Business 200 Series Smart Switch 1.2.7.76 and earlier, Small Business 300 Series Managed Switch 1.2.7.76 and earlier, and Small Business 500 Series Stackable Managed Switch 1.2.7.76 and earlier allow remote attackers to cause a denial of service (SSL/TLS layer outage) via malformed (1) SSH or (2) SSL packets, aka Bug ID CSCua30246. The SSH implementation in multiple Cisco products contains a denial-of-service (DoS) vulnerability. Hisashi Kojima, Masahiro Nakada of Fujitsu Laboratories Ltd. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.A remote attacker may be able to cause a denial-of-service (DoS). Cisco Small Business Switches is a small commercial switch device from Cisco. Cisco Small Business Switches has an unspecified error in handling SSH or SSL messages, allowing an attacker to exploit a vulnerability to send a specially crafted message to crash the service, causing a denial of service attack. Successful exploits may allow an attacker to cause denial-of-service conditions. This issue is tracked by Cisco Bug ID CSCua30246

Trust: 2.52

sources: NVD: CVE-2013-1154 // JVNDB: JVNDB-2013-000017 // CNVD: CNVD-2013-01689 // BID: 58374 // VULHUB: VHN-61156

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-01689

AFFECTED PRODUCTS

vendor:ciscomodel:300 series managed switchesscope:eqversion:sf302-08p

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sg300-10sfp

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sg300-28mp

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sg500x-24

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sg300-28p

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sf500-48p

Trust: 1.0

vendor:ciscomodel:200 series smart switchesscope:eqversion:sg200-50p

Trust: 1.0

vendor:ciscomodel:200 series smart switchesscope:eqversion:sg200-08

Trust: 1.0

vendor:ciscomodel:200 series smart switchesscope:eqversion:sf200-24

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sg300-10

Trust: 1.0

vendor:ciscomodel:200 series smart switchesscope:eqversion:sg200-26

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sg300-52p

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sg500-52p

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sf300-48

Trust: 1.0

vendor:ciscomodel:200 series smart switchesscope:eqversion:sf200-24p

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sg300-28

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sf500-24

Trust: 1.0

vendor:ciscomodel:200 series smart switchesscope:eqversion:sg200-18

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sf500-48

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sg500-28

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sf300-24p

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sf500-24p

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sg300-10mp

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sg300-52mp

Trust: 1.0

vendor:ciscomodel:200 series smart switchesscope:eqversion:sf200-48p

Trust: 1.0

vendor:ciscomodel:200 series smart switchesscope:eqversion:sg200-08p

Trust: 1.0

vendor:ciscomodel:200 series smart switchesscope:eqversion:sg200-50

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sg500-28p

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sg500x-24p

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sg500x-48p

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sg300-10p

Trust: 1.0

vendor:ciscomodel:200 series smart switchesscope:eqversion:sg200-26p

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sg300-20

Trust: 1.0

vendor:ciscomodel:200 series smart switches softwarescope:lteversion:1.2.7.76

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sf302-08mp

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sg500x-48

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sg300-52

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sf300-08

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sf300-24

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sf302-08

Trust: 1.0

vendor:ciscomodel:500 series stackable managed switchesscope:eqversion:sg500-52

Trust: 1.0

vendor:ciscomodel:200 series smart switchesscope:eqversion:sf200-48

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sf300-24mp

Trust: 1.0

vendor:ciscomodel:300 series managed switchesscope:eqversion:sf300-48p

Trust: 1.0

vendor:ciscomodel:small business 200 series smart switchscope:eqversion:(1.2.7.76 and prior)

Trust: 0.8

vendor:ciscomodel:small business 200 series smart switch softwarescope:eqversion:1.2.7.76 and prior

Trust: 0.8

vendor:ciscomodel:small business 300 series managed switchscope:eqversion:(1.2.7.76 and prior)

Trust: 0.8

vendor:ciscomodel:small business 500 series stackable managed switchscope:eqversion:(1.2.7.76 and prior)

Trust: 0.8

vendor:ciscomodel:small business managed switches seriesscope:eqversion:300

Trust: 0.6

vendor:ciscomodel:small business smart switches seriesscope:eqversion:200

Trust: 0.6

vendor:ciscomodel:small business stackable managed seriesscope:eqversion:500

Trust: 0.6

vendor:ciscomodel:200 series smart switches softwarescope:eqversion:1.2.7.76

Trust: 0.6

vendor:ciscomodel:small business series stackable managed switchscope:eqversion:5001.2.7.76

Trust: 0.3

vendor:ciscomodel:small business series managed switchscope:eqversion:3001.2.7.76

Trust: 0.3

vendor:ciscomodel:small business series smart switchscope:eqversion:2001.2.7.76

Trust: 0.3

sources: CNVD: CNVD-2013-01689 // BID: 58374 // JVNDB: JVNDB-2013-000017 // CNNVD: CNNVD-201303-137 // NVD: CVE-2013-1154

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-1154
value: MEDIUM

Trust: 1.0

IPA: JVNDB-2013-000017
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201303-137
value: MEDIUM

Trust: 0.6

VULHUB: VHN-61156
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-1154
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

IPA: JVNDB-2013-000017
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-61156
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-61156 // JVNDB: JVNDB-2013-000017 // CNNVD: CNNVD-201303-137 // NVD: CVE-2013-1154

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.1

sources: VULHUB: VHN-61156 // NVD: CVE-2013-1154

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201303-137

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201303-137

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-000017

PATCH

title:Cisco Small Business Switches SSH Packet Processing Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/viewAlert.x?alertId=27502

Trust: 0.8

title:Patch for Cisco Small Business Switches Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/32711

Trust: 0.6

sources: CNVD: CNVD-2013-01689 // JVNDB: JVNDB-2013-000017

EXTERNAL IDS

db:NVDid:CVE-2013-1154

Trust: 3.4

db:JVNid:JVN05132866

Trust: 2.5

db:JVNDBid:JVNDB-2013-000017

Trust: 2.5

db:CNNVDid:CNNVD-201303-137

Trust: 0.7

db:CNVDid:CNVD-2013-01689

Trust: 0.6

db:JVNid:JVN#05132866

Trust: 0.6

db:SECUNIAid:52476

Trust: 0.6

db:BIDid:58374

Trust: 0.4

db:VULHUBid:VHN-61156

Trust: 0.1

sources: CNVD: CNVD-2013-01689 // VULHUB: VHN-61156 // BID: 58374 // JVNDB: JVNDB-2013-000017 // CNNVD: CNNVD-201303-137 // NVD: CVE-2013-1154

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=27502

Trust: 2.6

url:http://jvn.jp/en/jp/jvn05132866/index.html

Trust: 2.5

url:http://jvndb.jvn.jp/jvndb/jvndb-2013-000017

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-1154

Trust: 0.8

url:http://www.ipa.go.jp/about/press/20130307.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-1154

Trust: 0.8

url:http://secunia.com/advisories/52476

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2013-01689 // VULHUB: VHN-61156 // BID: 58374 // JVNDB: JVNDB-2013-000017 // CNNVD: CNNVD-201303-137 // NVD: CVE-2013-1154

CREDITS

Hisashi Kojima and Masahiro Nakada, Fujitsu Laboratories LTD

Trust: 0.3

sources: BID: 58374

SOURCES

db:CNVDid:CNVD-2013-01689
db:VULHUBid:VHN-61156
db:BIDid:58374
db:JVNDBid:JVNDB-2013-000017
db:CNNVDid:CNNVD-201303-137
db:NVDid:CVE-2013-1154

LAST UPDATE DATE

2025-04-11T23:20:36.001000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-01689date:2013-03-11T00:00:00
db:VULHUBid:VHN-61156date:2013-03-08T00:00:00
db:BIDid:58374date:2013-03-06T00:00:00
db:JVNDBid:JVNDB-2013-000017date:2013-03-11T00:00:00
db:CNNVDid:CNNVD-201303-137date:2013-03-08T00:00:00
db:NVDid:CVE-2013-1154date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-01689date:2013-03-11T00:00:00
db:VULHUBid:VHN-61156date:2013-03-07T00:00:00
db:BIDid:58374date:2013-03-06T00:00:00
db:JVNDBid:JVNDB-2013-000017date:2013-03-07T00:00:00
db:CNNVDid:CNNVD-201303-137date:2013-03-08T00:00:00
db:NVDid:CVE-2013-1154date:2013-03-07T20:55:02.313