ZeroHour

CVE-2021-1542

CVSS 3.1
8.1 high
EPSS
1%p71
Published
()
Modified
Description

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.

Vendors
cisco
Products
sf220-24 firmware, sf220-24p firmware, sf220-48 firmware, sf220-48p firmware, sg220-26 firmware, sg220-26p firmware, sg220-28mp firmware, sg220-50 firmware, sg220-50p firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news