CVE-2021-34744
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD
Description
Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the Details section of this advisory.
Affected (16)
Products: Cisco: Business 220 8t E 2g Firmware, Business 220 8p E 2g Firmware, Business 220 8fp E 2g Firmware, Business 220 16t 2g Firmware, Business 220 16p 2g Firmware, Business 220 24t 4g Firmware, Business 220 24p 4g Firmware, Business 220 24fp 4g Firmware, Business 220 48t 4g Firmware, Business 220 48p 4g Firmware, Business 220 24t 4x Firmware, Business 220 24p 4x Firmware, Business 220 24fp 4x Firmware, Business 220 48t 4x Firmware, Business 220 48p 4x Firmware, Business 220 48fp 4x Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 8t E 2g | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 8p E 2g | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 8fp E 2g | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 16t 2g | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 16p 2g | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 24t 4g | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 24p 4g | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 24fp 4g | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 48t 4g | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 48p 4g | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 24t 4x | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 24p 4x | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 24fp 4x | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 48t 4x | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 48p 4x | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.6 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 220 48fp 4x | All versions |
Related CWEs
CWE-540
Inclusion of Sensitive Information in Source Code
Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.
CWE-798
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.