4.9

CVE-2021-34744

Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the Details section of this advisory.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoBusiness 220-8t-e-2g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-8t-e-2g Version-
CiscoBusiness 220-8p-e-2g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-8p-e-2g Version-
CiscoBusiness 220-8fp-e-2g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-8fp-e-2g Version-
CiscoBusiness 220-16t-2g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-16t-2g Version-
CiscoBusiness 220-16p-2g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-16p-2g Version-
CiscoBusiness 220-24t-4g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24t-4g Version-
CiscoBusiness 220-24p-4g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24p-4g Version-
CiscoBusiness 220-24fp-4g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24fp-4g Version-
CiscoBusiness 220-48t-4g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-48t-4g Version-
CiscoBusiness 220-48p-4g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-48p-4g Version-
CiscoBusiness 220-24t-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24t-4x Version-
CiscoBusiness 220-24p-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24p-4x Version-
CiscoBusiness 220-24fp-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24fp-4x Version-
CiscoBusiness 220-48t-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-48t-4x Version-
CiscoBusiness 220-48p-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-48p-4x Version-
CiscoBusiness 220-48fp-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-48fp-4x Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.614
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
psirt@cisco.com 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-540 Inclusion of Sensitive Information in Source Code

Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.