CVE-2021-34757
06.10.2021, 20:15
Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the Details section of this advisory.Enginsight
Vendor | Product | Version |
---|---|---|
cisco | business_220-8t-e-2g_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-8p-e-2g_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-8fp-e-2g_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-16t-2g_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-16p-2g_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-24t-4g_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-24p-4g_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-24fp-4g_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-48t-4g_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-48p-4g_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-24t-4x_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-24p-4x_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-24fp-4x_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-48t-4x_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-48p-4x_firmware | 𝑥 ≤ 1.2.0.6 |
cisco | business_220-48fp-4x_firmware | 𝑥 ≤ 1.2.0.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-540 - Inclusion of Sensitive Information in Source CodeSource code on a web server or repository often contains sensitive information and should generally not be accessible to users.
- CWE-798 - Use of Hard-coded CredentialsThe software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.