{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[],"affected_systems_content":"<ul> <li>Microgiciel de la gamme de commutateurs 250 Series Smart Switches versions ant\u00e9rieures \u00e0 2.5.9.16</li> <li>Microgiciel de la gamme de commutateurs 350 Series Managed Smart Switches versions ant\u00e9rieures \u00e0 2.5.9.16</li> <li>Microgiciel de la gamme de commutateurs 350X Series Stackable Managed Smart Switches versions ant\u00e9rieures \u00e0 2.5.9.16</li> <li>Microgiciel de la gamme de commutateurs 550X Series Stackable Managed Smart Switches versions ant\u00e9rieures \u00e0 2.5.9.16</li> <li>Microgiciel de la gamme de commutateurs Business 250 Series Smart Switches versions ant\u00e9rieures \u00e0 3.3.0.16</li> <li>Microgiciel de la gamme de commutateurs Business 350 Series Smart Switches versions ant\u00e9rieures \u00e0 3.3.0.16</li> <li>Microgiciel de la gamme de commutateurs Small Business 200 Series Smart Switches</li> <li>Microgiciel de la gamme de commutateurs Small Business 300 Series Managed Switches</li> <li>Microgiciel de la gamme de commutateurs Small Business 500 Series Stackable Managed Switches</li> </ul> <p>Les produits suivants ne sont plus maintenus par l'\u00e9diteur et ne disposeront pas de correctifs de s\u00e9curit\u00e9 : Small Business 200 Series Smart Switches, Small Business 300 Series Managed Switches, Small Business 500 Series Stackable Managed Switches</p> ","content":"## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2023-20160","url":"https://www.cve.org/CVERecord?id=CVE-2023-20160"},{"name":"CVE-2023-20162","url":"https://www.cve.org/CVERecord?id=CVE-2023-20162"},{"name":"CVE-2023-20159","url":"https://www.cve.org/CVERecord?id=CVE-2023-20159"},{"name":"CVE-2023-20024","url":"https://www.cve.org/CVERecord?id=CVE-2023-20024"},{"name":"CVE-2023-20158","url":"https://www.cve.org/CVERecord?id=CVE-2023-20158"},{"name":"CVE-2023-20189","url":"https://www.cve.org/CVERecord?id=CVE-2023-20189"},{"name":"CVE-2023-20161","url":"https://www.cve.org/CVERecord?id=CVE-2023-20161"},{"name":"CVE-2023-20156","url":"https://www.cve.org/CVERecord?id=CVE-2023-20156"},{"name":"CVE-2023-20157","url":"https://www.cve.org/CVERecord?id=CVE-2023-20157"}],"links":[],"reference":"CERTFR-2023-AVI-0401","revisions":[{"description":"Version initiale","revision_date":"2023-05-19T00:00:00.000000"}],"risks":[{"description":"D\u00e9ni de service \u00e0 distance"},{"description":"Ex\u00e9cution de code arbitraire \u00e0 distance"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans plusieurs gammes de\ncommutateurs <span class=\"textit\">Cisco</span>. Elles permettent \u00e0 un\nattaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une\natteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et un d\u00e9ni de service \u00e0\ndistance.\n","title":"Multiples vuln\u00e9rabilit\u00e9s dans les produits Cisco","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Cisco cisco-sa-sg-web-multi-S9g4Nkgv du 17 mai 2023","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv"}]}
