8.1

CVE-2021-34739

A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface of an affected device. This vulnerability is due to insufficient expiration of session credentials. An attacker could exploit this vulnerability by conducting a man-in-the-middle attack against an affected device to intercept valid session credentials and then replaying the intercepted credentials toward the same device at a later time. A successful exploit could allow the attacker to access the web-based management interface with administrator privileges.

Data is provided by the National Vulnerability Database (NVD)
CiscoSf250-24 Firmware Version <= 2.5
   CiscoSf250-24 Version-
CiscoSf250-24p Firmware Version <= 2.5
   CiscoSf250-24p Version-
CiscoSf250-48 Firmware Version <= 2.5
   CiscoSf250-48 Version-
CiscoSf250-48hp Firmware Version <= 2.5
   CiscoSf250-48hp Version-
CiscoSf250-08 Firmware Version <= 2.5
   CiscoSf250-08 Version-
CiscoSf250-08hp Firmware Version <= 2.5
   CiscoSf250-08hp Version-
CiscoSf250-10p Firmware Version <= 2.5
   CiscoSf250-10p Version-
CiscoSf250-18 Firmware Version <= 2.5
   CiscoSf250-18 Version-
CiscoSf250-26 Firmware Version <= 2.5
   CiscoSf250-26 Version-
CiscoSf250-26hp Firmware Version <= 2.5
   CiscoSf250-26hp Version-
CiscoSf250-26p Firmware Version <= 2.5
   CiscoSf250-26p Version-
CiscoSf250-50 Firmware Version <= 2.5
   CiscoSf250-50 Version-
CiscoSf250-50hp Firmware Version <= 2.5
   CiscoSf250-50hp Version-
CiscoSf250-50p Firmware Version <= 2.5
   CiscoSf250-50p Version-
CiscoSf250x-24 Firmware Version <= 2.5
   CiscoSf250x-24 Version-
CiscoSf250x-24p Firmware Version <= 2.5
   CiscoSf250x-24p Version-
CiscoSf250x-48 Firmware Version <= 2.5
   CiscoSf250x-48 Version-
CiscoSf250x-48p Firmware Version <= 2.5
   CiscoSf250x-48p Version-
CiscoSf350-08 Firmware Version <= 2.5
   CiscoSf350-08 Version-
CiscoSf350-24 Firmware Version <= 2.5
   CiscoSf350-24 Version-
CiscoSf350-24mp Firmware Version <= 2.5
   CiscoSf350-24mp Version-
CiscoSf350-24p Firmware Version <= 2.5
   CiscoSf350-24p Version-
CiscoSf350-48 Firmware Version <= 2.5
   CiscoSf350-48 Version-
CiscoSf350-8mp Firmware Version <= 2.5
   CiscoSf350-8mp Version-
CiscoSf350-48p Firmware Version <= 2.5
   CiscoSf350-48p Version-
CiscoSf352-08 Firmware Version <= 2.5
   CiscoSf352-08 Version-
CiscoSf352-08mp Firmware Version <= 2.5
   CiscoSf352-08mp Version-
CiscoSf352-08p Firmware Version <= 2.5
   CiscoSf352-08p Version-
CiscoSf350-8pd Firmware Version <= 2.5
   CiscoSf350-8pd Version-
CiscoSf350-10 Firmware Version <= 2.5
   CiscoSf350-10 Version-
CiscoSf350-10mp Firmware Version <= 2.5
   CiscoSf350-10mp Version-
CiscoSf350-10p Firmware Version <= 2.5
   CiscoSf350-10p Version-
CiscoSf350-10sfp Firmware Version <= 2.5
   CiscoSf350-10sfp Version-
CiscoSf350-20 Firmware Version <= 2.5
   CiscoSf350-20 Version-
CiscoSf350-28 Firmware Version <= 2.5
   CiscoSf350-28 Version-
CiscoSf350-28mp Firmware Version <= 2.5
   CiscoSf350-28mp Version-
CiscoSf350-28p Firmware Version <= 2.5
   CiscoSf350-28p Version-
CiscoSf350-28sfp Firmware Version <= 2.5
   CiscoSf350-28sfp Version-
CiscoSf350-52 Firmware Version <= 2.5
   CiscoSf350-52 Version-
CiscoSf350-52mp Firmware Version <= 2.5
   CiscoSf350-52mp Version-
CiscoSf350-52p Firmware Version <= 2.5
   CiscoSf350-52p Version-
CiscoSf355-10p Firmware Version <= 2.5
   CiscoSf355-10p Version-
CiscoSg350x-8pmd Firmware Version <= 2.5
   CiscoSg350x-8pmd Version-
CiscoSg350x-12pmv Firmware Version <= 2.5
   CiscoSg350x-12pmv Version-
CiscoSg350x-24 Firmware Version <= 2.5
   CiscoSg350x-24 Version-
CiscoSg350x-24p Firmware Version <= 2.5
   CiscoSg350x-24p Version-
CiscoSg350x-24mp Firmware Version <= 2.5
   CiscoSg350x-24mp Version-
CiscoSg350x-24pd Firmware Version <= 2.5
   CiscoSg350x-24pd Version-
CiscoSg350x-24pv Firmware Version <= 2.5
   CiscoSg350x-24pv Version-
CiscoSg350x-48 Firmware Version <= 2.5
   CiscoSg350x-48 Version-
CiscoSg350x-48p Firmware Version <= 2.5
   CiscoSg350x-48p Version-
CiscoSg350x-48mp Firmware Version <= 2.5
   CiscoSg350x-48mp Version-
CiscoSg350x-48pv Firmware Version <= 2.5
   CiscoSg350x-48pv Version-
CiscoSg350xg-2f10 Firmware Version <= 2.5
   CiscoSg350xg-2f10 Version-
CiscoSg350xg-24f Firmware Version <= 2.5
   CiscoSg350xg-24f Version-
CiscoSg350xg-24t Firmware Version <= 2.5
   CiscoSg350xg-24t Version-
CiscoSg350xg-48t Firmware Version <= 2.5
   CiscoSg350xg-48t Version-
CiscoSx350x-08 Firmware Version <= 2.5
   CiscoSx350x-08 Version-
CiscoSx350x-12 Firmware Version <= 2.5
   CiscoSx350x-12 Version-
CiscoSx350x-24f Firmware Version <= 2.5
   CiscoSx350x-24f Version-
CiscoSx350x-24 Firmware Version <= 2.5
   CiscoSx350x-24 Version-
CiscoSx350x-52 Firmware Version <= 2.5
   CiscoSx350x-52 Version-
CiscoSf550x-24 Firmware Version <= 2.5
   CiscoSf550x-24 Version-
CiscoSf550x-24p Firmware Version <= 2.5
   CiscoSf550x-24p Version-
CiscoSf550x-24mp Firmware Version <= 2.5
   CiscoSf550x-24mp Version-
CiscoSf550x-48 Firmware Version <= 2.5
   CiscoSf550x-48 Version-
CiscoSf550x-48p Firmware Version <= 2.5
   CiscoSf550x-48p Version-
CiscoSf550x-48mp Firmware Version <= 2.5
   CiscoSf550x-48mp Version-
CiscoSg550x-24 Firmware Version <= 2.5
   CiscoSg550x-24 Version-
CiscoSg550x-24p Firmware Version <= 2.5
   CiscoSg550x-24p Version-
CiscoSg550x-24mp Firmware Version <= 2.5
   CiscoSg550x-24mp Version-
CiscoSg550x-24mpp Firmware Version <= 2.5
   CiscoSg550x-24mpp Version-
CiscoSg550x-48 Firmware Version <= 2.5
   CiscoSg550x-48 Version-
CiscoSg550x-48p Firmware Version <= 2.5
   CiscoSg550x-48p Version-
CiscoSg550x-48mp Firmware Version <= 2.5
   CiscoSg550x-48mp Version-
CiscoSg550xg-8f8t Firmware Version <= 2.5
   CiscoSg550xg-8f8t Version-
CiscoSg550xg-24f Firmware Version <= 2.5
   CiscoSg550xg-24f Version-
CiscoSg550xg-24t Firmware Version <= 2.5
   CiscoSg550xg-24t Version-
CiscoSg550xg-48t Firmware Version <= 2.5
   CiscoSg550xg-48t Version-
CiscoSx550x-12f Firmware Version <= 2.5
   CiscoSx550x-12f Version-
CiscoSx550x-16ft Firmware Version <= 2.5
   CiscoSx550x-16ft Version-
CiscoSx550x-24ft Firmware Version <= 2.5
   CiscoSx550x-24ft Version-
CiscoSx550x-24f Firmware Version <= 2.5
   CiscoSx550x-24f Version-
CiscoSx550x-24 Firmware Version <= 2.5
   CiscoSx550x-24 Version-
CiscoSx550x-52 Firmware Version <= 2.5
   CiscoSx550x-52 Version-
CiscoCbs250-8t-d Firmware Version <= 3.1
   CiscoCbs250-8t-d Version-
CiscoCbs250-8pp-d Firmware Version <= 3.1
   CiscoCbs250-8pp-d Version-
CiscoCbs250-8t-e-2g Firmware Version <= 3.1
   CiscoCbs250-8t-e-2g Version-
CiscoCbs250-8pp-e-2g Firmware Version <= 3.1
   CiscoCbs250-8pp-e-2g Version-
CiscoCbs250-8p-e-2g Firmware Version <= 3.1
   CiscoCbs250-8p-e-2g Version-
CiscoCbs250-8fp-e-2g Firmware Version <= 3.1
   CiscoCbs250-8fp-e-2g Version-
CiscoCbs250-16t-2g Firmware Version <= 3.1
   CiscoCbs250-16t-2g Version-
CiscoCbs250-16p-2g Firmware Version <= 3.1
   CiscoCbs250-16p-2g Version-
CiscoCbs250-24t-4g Firmware Version <= 3.1
   CiscoCbs250-24t-4g Version-
CiscoCbs250-24pp-4g Firmware Version <= 3.1
   CiscoCbs250-24pp-4g Version-
CiscoCbs250-24p-4g Firmware Version <= 3.1
   CiscoCbs250-24p-4g Version-
CiscoCbs250-24fp-4g Firmware Version <= 3.1
   CiscoCbs250-24fp-4g Version-
CiscoCbs250-48t-4g Firmware Version <= 3.1
   CiscoCbs250-48t-4g Version-
CiscoCbs250-48pp-4g Firmware Version <= 3.1
   CiscoCbs250-48pp-4g Version-
CiscoCbs250-48p-4g Firmware Version <= 3.1
   CiscoCbs250-48p-4g Version-
CiscoCbs250-24t-4x Firmware Version <= 3.1
   CiscoCbs250-24t-4x Version-
CiscoCbs250-24p-4x Firmware Version <= 3.1
   CiscoCbs250-24p-4x Version-
CiscoCbs250-24fp-4x Firmware Version <= 3.1
   CiscoCbs250-24fp-4x Version-
CiscoCbs250-48t-4x Firmware Version <= 3.1
   CiscoCbs250-48t-4x Version-
CiscoCbs250-48p-4x Firmware Version <= 3.1
   CiscoCbs250-48p-4x Version-
CiscoCbs350-8t-e-2g Firmware Version <= 3.1
   CiscoCbs350-8t-e-2g Version-
CiscoCbs350-8p-2g Firmware Version <= 3.1
   CiscoCbs350-8p-2g Version-
CiscoCbs350-8p-e-2g Firmware Version <= 3.1
   CiscoCbs350-8p-e-2g Version-
CiscoCbs350-8fp-2g Firmware Version <= 3.1
   CiscoCbs350-8fp-2g Version-
CiscoCbs350-8fp-e-2g Firmware Version <= 3.1
   CiscoCbs350-8fp-e-2g Version-
CiscoCbs350-8s-e-2g Firmware Version <= 3.1
   CiscoCbs350-8s-e-2g Version-
CiscoCbs350-16t-2g Firmware Version <= 3.1
   CiscoCbs350-16t-2g Version-
CiscoCbs350-16t-e-2g Firmware Version <= 3.1
   CiscoCbs350-16t-e-2g Version-
CiscoCbs350-16p-2g Firmware Version <= 3.1
   CiscoCbs350-16p-2g Version-
CiscoCbs350-16p-e-2g Firmware Version <= 3.1
   CiscoCbs350-16p-e-2g Version-
CiscoCbs350-16fp-2g Firmware Version <= 3.1
   CiscoCbs350-16fp-2g Version-
CiscoCbs350-24t-4g Firmware Version <= 3.1
   CiscoCbs350-24t-4g Version-
CiscoCbs350-24p-4g Firmware Version <= 3.1
   CiscoCbs350-24p-4g Version-
CiscoCbs350-24fp-4g Firmware Version <= 3.1
   CiscoCbs350-24fp-4g Version-
CiscoCbs350-24s-4g Firmware Version <= 3.1
   CiscoCbs350-24s-4g Version-
CiscoCbs350-48t-4g Firmware Version <= 3.1
   CiscoCbs350-48t-4g Version-
CiscoCbs350-48p-4g Firmware Version <= 3.1
   CiscoCbs350-48p-4g Version-
CiscoCbs350-48fp-4g Firmware Version <= 3.1
   CiscoCbs350-48fp-4g Version-
CiscoCbs350-24t-4x Firmware Version <= 3.1
   CiscoCbs350-24t-4x Version-
CiscoCbs350-24p-4x Firmware Version <= 3.1
   CiscoCbs350-24p-4x Version-
CiscoCbs350-24fp-4x Firmware Version <= 3.1
   CiscoCbs350-24fp-4x Version-
CiscoCbs350-48t-4x Firmware Version <= 3.1
   CiscoCbs350-48t-4x Version-
CiscoCbs350-48p-4x Firmware Version <= 3.1
   CiscoCbs350-48p-4x Version-
CiscoCbs350-48fp-4x Firmware Version <= 3.1
   CiscoCbs350-48fp-4x Version-
CiscoCbs350-8mgp-2x Firmware Version <= 3.1
   CiscoCbs350-8mgp-2x Version-
CiscoCbs350-8mp-2x Firmware Version <= 3.1
   CiscoCbs350-8mp-2x Version-
CiscoCbs350-24mgp-4x Firmware Version <= 3.1
   CiscoCbs350-24mgp-4x Version-
CiscoCbs350-12np-4x Firmware Version <= 3.1
   CiscoCbs350-12np-4x Version-
CiscoCbs350-24ngp-4x Firmware Version <= 3.1
   CiscoCbs350-24ngp-4x Version-
CiscoCbs350-48ngp-4x Firmware Version <= 3.1
   CiscoCbs350-48ngp-4x Version-
CiscoCbs350-8xt Firmware Version <= 3.1
   CiscoCbs350-8xt Version-
CiscoCbs350-12xs Firmware Version <= 3.1
   CiscoCbs350-12xs Version-
CiscoCbs350-12xt Firmware Version <= 3.1
   CiscoCbs350-12xt Version-
CiscoCbs350-16xts Firmware Version <= 3.1
   CiscoCbs350-16xts Version-
CiscoCbs350-24xs Firmware Version <= 3.1
   CiscoCbs350-24xs Version-
CiscoCbs350-24xt Firmware Version <= 3.1
   CiscoCbs350-24xt Version-
CiscoCbs350-24xts Firmware Version <= 3.1
   CiscoCbs350-24xts Version-
CiscoCbs350-48xt-4x Firmware Version <= 3.1
   CiscoCbs350-48xt-4x Version-
CiscoEsw2-350g-52 Firmware Version <= 2.5
   CiscoEsw2-350g-52 Version-
CiscoEsw2-350g-52dc Firmware Version <= 2.5
   CiscoEsw2-350g-52dc Version-
CiscoEsw2-550x-48 Firmware Version <= 2.5
   CiscoEsw2-550x-48 Version-
CiscoEsw2-550x-48dc Firmware Version <= 2.5
   CiscoEsw2-550x-48dc Version-
CiscoSf200-24 Firmware Version-
   CiscoSf200-24 Version-
CiscoSf200-24p Firmware Version-
   CiscoSf200-24p Version-
CiscoSf200-24fp Firmware Version-
   CiscoSf200-24fp Version-
CiscoSf200-48 Firmware Version-
   CiscoSf200-48 Version-
CiscoSf200-48p Firmware Version-
   CiscoSf200-48p Version-
CiscoSg200-08 Firmware Version-
   CiscoSg200-08 Version-
CiscoSg200-08p Firmware Version-
   CiscoSg200-08p Version-
CiscoSg200-10fp Firmware Version-
   CiscoSg200-10fp Version-
CiscoSg200-18 Firmware Version-
   CiscoSg200-18 Version-
CiscoSg200-26 Firmware Version-
   CiscoSg200-26 Version-
CiscoSg200-26p Firmware Version-
   CiscoSg200-26p Version-
CiscoSg200-26fp Firmware Version-
   CiscoSg200-26fp Version-
CiscoSg200-50 Firmware Version-
   CiscoSg200-50 Version-
CiscoSg200-50p Firmware Version-
   CiscoSg200-50p Version-
CiscoSg200-50fp Firmware Version-
   CiscoSg200-50fp Version-
CiscoSf300-08 Firmware Version1.4.11.02
   CiscoSf300-08 Version-
CiscoSf302-08 Firmware Version1.4.11.02
   CiscoSf302-08 Version-
CiscoSf302-08p Firmware Version1.4.11.02
   CiscoSf302-08p Version-
CiscoSf302-08pp Firmware Version1.4.11.02
   CiscoSf302-08pp Version-
CiscoSf302-08mp Firmware Version1.4.11.02
   CiscoSf302-08mp Version-
CiscoSf302-08mpp Firmware Version1.4.11.02
   CiscoSf302-08mpp Version-
CiscoSf300-24 Firmware Version1.4.11.02
   CiscoSf300-24 Version-
CiscoSf300-24p Firmware Version1.4.11.02
   CiscoSf300-24p Version-
CiscoSf300-24pp Firmware Version1.4.11.02
   CiscoSf300-24pp Version-
CiscoSf300-24mp Firmware Version1.4.11.02
   CiscoSf300-24mp Version-
CiscoSf300-48 Firmware Version1.4.11.02
   CiscoSf300-48 Version-
CiscoSf300-48p Firmware Version1.4.11.02
   CiscoSf300-48p Version-
CiscoSf300-48pp Firmware Version1.4.11.02
   CiscoSf300-48pp Version-
CiscoSg300-10 Firmware Version1.4.11.02
   CiscoSg300-10 Version-
CiscoSg300-10sfp Firmware Version1.4.11.02
   CiscoSg300-10sfp Version-
CiscoSg300-10p Firmware Version1.4.11.02
   CiscoSg300-10p Version-
CiscoSg300-10pp Firmware Version1.4.11.02
   CiscoSg300-10pp Version-
CiscoSg300-10mp Firmware Version1.4.11.02
   CiscoSg300-10mp Version-
CiscoSg300-10mpp Firmware Version1.4.11.02
   CiscoSg300-10mpp Version-
CiscoSg300-20 Firmware Version1.4.11.02
   CiscoSg300-20 Version-
CiscoSg300-28 Firmware Version1.4.11.02
   CiscoSg300-28 Version-
CiscoSg300-28p Firmware Version1.4.11.02
   CiscoSg300-28p Version-
CiscoSg300-28pp Firmware Version1.4.11.02
   CiscoSg300-28pp Version-
CiscoSg300-28mp Firmware Version1.4.11.02
   CiscoSg300-28mp Version-
CiscoSg300-52 Firmware Version1.4.11.02
   CiscoSg300-52 Version-
CiscoSg300-52p Firmware Version1.4.11.02
   CiscoSg300-52p Version-
CiscoSg300-52mp Firmware Version1.4.11.02
   CiscoSg300-52mp Version-
CiscoSg300-28sfp Firmware Version1.4.11.02
   CiscoSg300-28sfp Version-
CiscoSf500-24 Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSf500-24 Version-
CiscoSf500-24p Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSf500-24p Version-
CiscoSf500-24mp Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSf500-24mp Version-
CiscoSf500-48 Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSf500-48 Version-
CiscoSf500-48p Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSf500-48p Version-
CiscoSf500-48mp Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSf500-48mp Version-
CiscoSg500-28 Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500-28 Version-
CiscoSg500-28p Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500-28p Version-
CiscoSg500-28mpp Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500-28mpp Version-
CiscoSg500-52 Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500-52 Version-
CiscoSg500-52p Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500-52p Version-
CiscoSg500-52mp Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500-52mp Version-
CiscoSg500x-24 Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500x-24 Version-
CiscoSg500x-24p Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500x-24p Version-
CiscoSg500x-24mpp Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500x-24mpp Version-
CiscoSg500x-48 Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500x-48 Version-
CiscoSg500x-48p Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500x-48p Version-
CiscoSg500x-48mp Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500x-48mp Version-
CiscoSg500xg-8f8t Firmware Version >= 2.5.5.0 < 2.5.8.12
   CiscoSg500xg-8f8t Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.5% 0.65
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
psirt@cisco.com 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-613 Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."