VYPR
Medium severity6.5NVD Advisory· Published Sep 21, 2017· Updated May 13, 2026

CVE-2017-6720

CVE-2017-6720

Description

A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition. The vulnerability is due to improper processing of SSH connections. An attacker could exploit this vulnerability by logging in to an affected switch via SSH and sending a malicious SSH message. This vulnerability affects the following Cisco products when SSH is enabled: Small Business 300 Series Managed Switches, Small Business 500 Series Stackable Managed Switches, 350 Series Managed Switches, 350X Series Stackable Managed Switches, 550X Series Stackable Managed Switches, ESW2 Series Advanced Switches. Cisco Bug IDs: CSCvb48377.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A flaw in SSH processing in Cisco Small Business Managed Switches allows an authenticated remote attacker to trigger a denial of service via device reload.

Vulnerability

The SSH subsystem in Cisco Small Business Managed Switches software improperly processes SSH connections, leading to a potential denial of service. Affected products include Small Business 300, 500, 350, 350X, 550X Series, and ESW2 Series switches when SSH is enabled. [1]

Exploitation

An authenticated remote attacker can exploit by logging in via SSH and sending a malicious SSH message, causing a switch reload. No additional privileges beyond SSH access are required. [1]

Impact

Successful exploitation results in a denial of service due to device reload, which temporarily disrupts network services. [1]

Mitigation

Cisco has released free software updates to address this vulnerability. Customers should upgrade to the fixed versions as specified in the advisory [1]. No workarounds are provided, but disabling SSH if not required may mitigate risk.

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

88

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.