8.8

CVE-2021-1400

Cisco Small Business 100, 300, and 500 Series Wireless Access Points Vulnerabilities

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to obtain sensitive information from or inject arbitrary commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Wap125 Firmware Version <= 1.0.3.1
   Cisco ≫ Wap125 Version -
Cisco ≫ Wap131 Firmware Version <= 1.0.2.17
   Cisco ≫ Wap131 Version -
Cisco ≫ Wap150 Firmware Version <= 1.1.2.4
   Cisco ≫ Wap150 Version -
Cisco ≫ Wap351 Firmware Version <= 1.0.2.17
   Cisco ≫ Wap351 Version -
Cisco ≫ Wap361 Firmware Version <= 1.1.2.4
   Cisco ≫ Wap361 Version -
Cisco ≫ Wap581 Firmware Version <= 1.0.3.1
   Cisco ≫ Wap581 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.29% 0.664
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
Cisco PSIRT 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

http://jvn.jp/en/jp/JVN71263107/index.html
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-wap-multi-ZAfKGXhF
Vendor Advisory