5.5

CVE-2021-34757

Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the Details section of this advisory.

Data is provided by the National Vulnerability Database (NVD)
CiscoBusiness 220-8t-e-2g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-8t-e-2g Version-
CiscoBusiness 220-8p-e-2g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-8p-e-2g Version-
CiscoBusiness 220-8fp-e-2g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-8fp-e-2g Version-
CiscoBusiness 220-16t-2g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-16t-2g Version-
CiscoBusiness 220-16p-2g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-16p-2g Version-
CiscoBusiness 220-24t-4g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24t-4g Version-
CiscoBusiness 220-24p-4g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24p-4g Version-
CiscoBusiness 220-24fp-4g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24fp-4g Version-
CiscoBusiness 220-48t-4g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-48t-4g Version-
CiscoBusiness 220-48p-4g Firmware Version <= 1.2.0.6
   CiscoBusiness 220-48p-4g Version-
CiscoBusiness 220-24t-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24t-4x Version-
CiscoBusiness 220-24p-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24p-4x Version-
CiscoBusiness 220-24fp-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-24fp-4x Version-
CiscoBusiness 220-48t-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-48t-4x Version-
CiscoBusiness 220-48p-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-48p-4x Version-
CiscoBusiness 220-48fp-4x Firmware Version <= 1.2.0.6
   CiscoBusiness 220-48fp-4x Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.28% 0.485
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 0.3 5.2
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:P/A:N
psirt@cisco.com 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-540 Inclusion of Sensitive Information in Source Code

Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.