CVE-2013-1154
Last modified
CVE-2013-1154 is a vulnerability of currently unknown severity. The Cisco Small Business 200 Series Smart Switch 1.2.7.76 and earlier, Small Business 300 Series Managed Switch 1.2.7.76 and earlier, and Small Business 500 Series Stackable Managed Switch 1.2.7.76 and earlier allow remote attackers to cause a denial of service (SSL/TLS layer outage) via malformed (1) SSH or (2) SSL packets, aka Bug ID CSCua30246.. EPSS estimates a 1.55% chance of exploitation in the next 30 days.
Description
The Cisco Small Business 200 Series Smart Switch 1.2.7.76 and earlier, Small Business 300 Series Managed Switch 1.2.7.76 and earlier, and Small Business 500 Series Stackable Managed Switch 1.2.7.76 and earlier allow remote attackers to cause a denial of service (SSL/TLS layer outage) via malformed (1) SSH or (2) SSL packets, aka Bug ID CSCua30246.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | 200 Series Smart Switches | sf200-24 |
| Cisco | 200 Series Smart Switches | sf200-24p |
| Cisco | 200 Series Smart Switches | sf200-48 |
| Cisco | 200 Series Smart Switches | sf200-48p |
| Cisco | 200 Series Smart Switches | sg200-08 |
| Cisco | 200 Series Smart Switches | sg200-08p |
| Cisco | 200 Series Smart Switches | sg200-18 |
| Cisco | 200 Series Smart Switches | sg200-26 |
| Cisco | 200 Series Smart Switches | sg200-26p |
| Cisco | 200 Series Smart Switches | sg200-50 |
| Cisco | 200 Series Smart Switches | sg200-50p |
| Cisco | 300 Series Managed Switches | sf300-08 |
| Cisco | 300 Series Managed Switches | sf300-24 |
| Cisco | 300 Series Managed Switches | sf300-24mp |
| Cisco | 300 Series Managed Switches | sf300-24p |
| Cisco | 300 Series Managed Switches | sf300-48 |
| Cisco | 300 Series Managed Switches | sf300-48p |
| Cisco | 300 Series Managed Switches | sf302-08 |
| Cisco | 300 Series Managed Switches | sf302-08mp |
| Cisco | 300 Series Managed Switches | sf302-08p |
| Cisco | 300 Series Managed Switches | sg300-10 |
| Cisco | 300 Series Managed Switches | sg300-10mp |
| Cisco | 300 Series Managed Switches | sg300-10p |
| Cisco | 300 Series Managed Switches | sg300-10sfp |
| Cisco | 300 Series Managed Switches | sg300-20 |
| Cisco | 300 Series Managed Switches | sg300-28 |
| Cisco | 300 Series Managed Switches | sg300-28mp |
| Cisco | 300 Series Managed Switches | sg300-28p |
| Cisco | 300 Series Managed Switches | sg300-52 |
| Cisco | 300 Series Managed Switches | sg300-52mp |
| Cisco | 300 Series Managed Switches | sg300-52p |
| Cisco | 200 Series Smart Switches Software | <= 1.2.7.76 |
| Cisco | 500 Series Stackable Managed Switches | sf500-24 |
| Cisco | 500 Series Stackable Managed Switches | sf500-24p |
| Cisco | 500 Series Stackable Managed Switches | sf500-48 |
| Cisco | 500 Series Stackable Managed Switches | sf500-48p |
| Cisco | 500 Series Stackable Managed Switches | sg500-28 |
| Cisco | 500 Series Stackable Managed Switches | sg500-28p |
| Cisco | 500 Series Stackable Managed Switches | sg500-52 |
| Cisco | 500 Series Stackable Managed Switches | sg500-52p |
| Cisco | 500 Series Stackable Managed Switches | sg500x-24 |
| Cisco | 500 Series Stackable Managed Switches | sg500x-24p |
| Cisco | 500 Series Stackable Managed Switches | sg500x-48 |
| Cisco | 500 Series Stackable Managed Switches | sg500x-48p |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1154?
How severe is CVE-2013-1154?
How do I fix CVE-2013-1154?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-1148The General Responder implementation in the IP Service Level…
- CVE-2013-1149Cisco Adaptive Security Appliances (ASA) devices with softwa…
- CVE-2013-1150The authentication-proxy implementation on Cisco Adaptive Se…
- CVE-2013-1151Cisco Adaptive Security Appliances (ASA) devices with softwa…
- CVE-2013-1152Cisco Adaptive Security Appliances (ASA) devices with softwa…
- CVE-2013-1153Cross-site request forgery (CSRF) vulnerability in the web i…
- CVE-2013-1155The auth-proxy functionality in Cisco Firewall Services Modu…
- CVE-2013-1156Directory traversal vulnerability in Cisco Prime Central for…
- CVE-2013-1157Cross-site scripting (XSS) vulnerability in the IBM Tivoli M…
- CVE-2013-1158Cross-site scripting (XSS) vulnerability in the IBM Tivoli M…
- CVE-2013-1159Cross-site scripting (XSS) vulnerability in the Netcool Impa…
- CVE-2013-1160Cross-site scripting (XSS) vulnerability in the OpenView web…
Are you affected by CVE-2013-1154?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
