cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1254
Views
0
Helpful
5
Replies

SG300-28PP Crashes with multiple failed login attempts

Hello,

 

I have a few Cisco SG300-28PP switches at a customer location.  We are using Auvik to monitor these systems and just enabled the CLI functionality.  Upon doing so, several of the switches started rebooting.

 

On Auvik's website I found this

 

https://support.auvik.com/hc/en-us/articles/208634056-Known-issue-with-Cisco-SG-series-devices-and-unknown-logins

 

I am currently on Software version 1.4.2.4 but do not see anything in the release notes that indicates a software upgrade will resolve this issue.  I have made the necessary tweaks to hopefully prevent this from happening again but this bug seams like it could be weaponized and create some havoc pretty easily.  Has Cisco acknowledged this bug?  Is there a fix in the works?

 

 

 

 

 

5 Replies 5

Aleksandra Dargiel
Cisco Employee
Cisco Employee
Hi Tyler,
There is a big vulnerability we need to look into it, so please contact support team using local contact method and open ticket. they will gather needed information and forward this ticket to relevant team:

https://www.cisco.com/c/en/us/support/web/tsd-cisco-small-business-support-center-contacts.html

Regards,
Aleksandra

P.S. Please PM once ticket is opened.

I am attempting to at the moment but the customer purchased the units on the gray market so I am having difficulty gaining any traction with support.

Hi Tyler,

In this case first of all ensure you are running latest firmware and boot code as well.
firmware 1.4.8.06 boot code: 1.4.1.03
https://software.cisco.com/download/release.html?mdfid=284867262&softwareid=282463181&release=1.4.8.06&relind=AVAILABLE&rellifecycle=&reltype=latest

if this is still valid issue it should be possible to work with support towards resolution as this issue may affect not only you.

Regards,
Aleksandra

Hello,  The latest firmware resolves the issue. Thank you.

Hi Aleksandra,

When you say boot code: 1.4.1.03, I think it is a mistake, as far as I know, the latest boot code is version 1.3.5.06 isn't it?