CVE-2021-34744

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
06/10/2021
Last modified:
07/11/2023

Description

Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the Details section of this advisory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:business_220-8t-e-2g_firmware:*:*:*:*:*:*:*:* 1.2.0.6 (including)
cpe:2.3:h:cisco:business_220-8t-e-2g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:business_220-8p-e-2g_firmware:*:*:*:*:*:*:*:* 1.2.0.6 (including)
cpe:2.3:h:cisco:business_220-8p-e-2g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:business_220-8fp-e-2g_firmware:*:*:*:*:*:*:*:* 1.2.0.6 (including)
cpe:2.3:h:cisco:business_220-8fp-e-2g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:business_220-16t-2g_firmware:*:*:*:*:*:*:*:* 1.2.0.6 (including)
cpe:2.3:h:cisco:business_220-16t-2g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:business_220-16p-2g_firmware:*:*:*:*:*:*:*:* 1.2.0.6 (including)
cpe:2.3:h:cisco:business_220-16p-2g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:business_220-24t-4g_firmware:*:*:*:*:*:*:*:* 1.2.0.6 (including)
cpe:2.3:h:cisco:business_220-24t-4g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:business_220-24p-4g_firmware:*:*:*:*:*:*:*:* 1.2.0.6 (including)
cpe:2.3:h:cisco:business_220-24p-4g:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:business_220-24fp-4g_firmware:*:*:*:*:*:*:*:* 1.2.0.6 (including)