S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Feb 1, 2024

CVE-2019-1943 Scanner

Detects 'Open Redirect' vulnerability in Cisco Small Business 200,300 and 500 Series Switches affects v. 1.3.7.18.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-1943
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting a user's HTTP request and modifying it into a request that causes the web interface to redirect the user to a specific malicious URL. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Cisco Small Business 300 Series Managed Switchesby Cisco
1.3.7.18
Updated Aug 21, 2026View on NVD →
Detail

Cisco Small Business 200, 300, and 500 Series Switches are networking devices designed to connect multiple computers in a local area network (LAN). These switches are widely used in small businesses as they offer advanced features such as network security, Quality of Service (QoS), and traffic management. They facilitate the transfer of data between devices in a secure and efficient manner, making them an essential component for any business that relies on a LAN for their operations.

However, despite their usefulness, these switches are not immune to vulnerabilities. One such vulnerability is identified with the CVE-2019-1943 code. This vulnerability is caused by an input validation issue in the web interface of the switches' software. An attacker can exploit this weakness by intercepting a user's HTTP request and redirecting them to a malicious website without their knowledge.

When this vulnerability is exploited, it can lead to dire consequences for the user. The attacker can gain access to sensitive information stored on the user's devices, such as login credentials, personal and financial details. They can also remotely control the user's devices, using them to launch further attacks against other systems. Moreover, this vulnerability can also be used for phishing attacks, which can have severe implications for users who unknowingly visit a malicious site.

To mitigate this issue and stay ahead of potential vulnerabilities, companies need to have a robust and reliable vulnerability management plan. s4e.io provides advanced features that offer professional-grade security assessments to help businesses identify any vulnerabilities in their digital assets and take appropriate measures to safeguard them. With s4e.io, companies can put their minds at ease knowing that their digital security is in capable hands.

 

REFERENCES

Solution Advice

To safeguard against the CVE-2019-1943 vulnerability, there are several precautions that can be taken, including:

  • Updating the switches' software to the latest version that addresses the vulnerability.
  • Restricting access to the web interface of the switches only to trusted sources.
  • Disabling the web interface of the switches if it is not required.
  • Using strong and unique login credentials for the switches that are not shared with others.
  • Deploying an intrusion detection system (IDS) on the network, which monitors traffic and detects attempts to exploit vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-1943 scanner - Open Redirect vulnerability in Cisco Small Business 200,300 and 500 Series Switches S4E