← Vulnerability feed

Vulnerability record · CVE-2019-1913 · published 7 August 2019

CVE-2019-1913: Cisco sf-220-24 firmware memory buffer overflow vulnerability

Cisco · Sf 220 24 Firmware

Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating system. The vulnerabilities are due to insufficient validation of user-supplied input and improper boundary checks when reading data into an internal buffer. An attacker could exploit these vulnerabilities by sending malicious requests to the web management interface of an affected device. Depending on the configuration of the affected switch, the malicious requests must be sent via HTTP or HTTPS.

9.8 CVSS 3.0 Critical EPSS 26% · top 2.1% CWE-119 · Memory buffer overflow
9.8CVSS 3.0 base score, v2 10.0
26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating system. The vulnerabilities are due to insufficient validation of user-supplied input and improper boundary checks when reading data into an internal buffer. An attacker could exploit these vulnerabilities by sending malicious requests to the web management interface of an affected device. Depending on the configuration of the affected switch, the malicious requests must be sent via HTTP or HTTPS.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-1913 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2019-1912Cisco sf-220-24 firmware improper authorization vulnerabilityA vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to …EPSS 17%8.1CVE-2021-1542Cisco sf220-24 firmware improper authentication vulnerabilityMultiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the fo…EPSS 1.4%7.2CVE-2021-1541Cisco sf220-24 firmware improper authentication vulnerabilityMultiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the fo…EPSS 8.8%7.2CVE-2019-1914Cisco sf-220-24 firmware improper input validation vulnerabilityA vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to pe…EPSS 25%6.1CVE-2021-1571Cisco sf220-24 firmware improper authentication vulnerabilityMultiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the fo…EPSS 9.7%6.1CVE-2021-1543Cisco sf220-24 firmware improper authentication vulnerabilityMultiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the fo…EPSS 9.3%9.5CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed

Source: NIST National Vulnerability Database (record CVE-2019-1913), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.