← Back

CVE-2021-1542

nvd nist
Published: Jun 16, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.

Affected (9)

9 products
Sf220 24 Firmware
Sf220 24p Firmware
Sf220 48 Firmware
Sf220 48p Firmware
Sg220 26 Firmware
Sg220 26p Firmware
Sg220 28mp Firmware
Sg220 50 Firmware
Sg220 50p Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.6
Running on/withPlatform Versions
Cisco
Sf220 24
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.6
Running on/withPlatform Versions
Cisco
Sf220 24p
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.6
Running on/withPlatform Versions
Cisco
Sf220 48
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.6
Running on/withPlatform Versions
Cisco
Sf220 48p
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.6
Running on/withPlatform Versions
Cisco
Sg220 26
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.6
Running on/withPlatform Versions
Cisco
Sg220 26p
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.6
Running on/withPlatform Versions
Cisco
Sg220 28mp
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.6
Running on/withPlatform Versions
Cisco
Sg220 50
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.6
Running on/withPlatform Versions
Cisco
Sg220 50p
All versions

Timeline

No history available yet.