5.5
CVE-2021-34757
- EPSS 0.28%
- Published 06.10.2021 20:15:10
- Last modified 21.11.2024 06:11:07
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the Details section of this advisory.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Business 220-8t-e-2g Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-8p-e-2g Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-8fp-e-2g Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-16t-2g Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-16p-2g Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-24t-4g Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-24p-4g Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-24fp-4g Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-48t-4g Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-48p-4g Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-24t-4x Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-24p-4x Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-24fp-4x Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-48t-4x Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-48p-4x Firmware Version <= 1.2.0.6
Cisco ≫ Business 220-48fp-4x Firmware Version <= 1.2.0.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.28% | 0.485 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 0.3 | 5.2 |
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
nvd@nist.gov | 3.6 | 3.9 | 4.9 |
AV:L/AC:L/Au:N/C:P/I:P/A:N
|
psirt@cisco.com | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-540 Inclusion of Sensitive Information in Source Code
Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.