Cisco
Cisco Sf302-08 Firmware: vulnerabilidades y CVE
Cisco Sf302-08 Firmware tiene 32 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE32
Últimos 12 meses0
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-20188 | Media (4.8) | 0.48% | — | 28 jun 2023 | A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches… |
| CVE-2023-20189 | Crítica (9.8) | 11% | — | 18 may 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20162 | Crítica (9.8) | 1.2% | — | 18 may 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20161 | Crítica (9.8) | 10% | — | 18 may 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20160 | Crítica (9.8) | 10% | — | 18 may 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20159 | Crítica (9.8) | 10% | — | 18 may 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20158 | Crítica (9.8) | 1.2% | — | 18 may 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20157 | Crítica (9.8) | 1.2% | — | 18 may 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20156 | Crítica (9.8) | 1.2% | — | 18 may 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20024 | Alta (7.5) | 1.3% | — | 18 may 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2021-40127 | Media (5.3) | 1.3% | — | 4 nov 2021 | A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches… |
| CVE-2021-34739 | Alta (8.1) | 1.7% | — | 4 nov 2021 | A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized… |
| CVE-2019-15993 | Media (5.3) | 10% | — | 23 sept 2020 | A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper… |
| CVE-2020-3496 | Media (5.3) | 1.7% | — | 26 ago 2020 | A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.… |
| CVE-2020-3363 | Alta (8.6) | 1.8% | — | 17 ago 2020 | A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.… |
| CVE-2020-3297 | Crítica (9.8) | 3.0% | — | 2 jul 2020 | A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to defeat authentication protections and gain… |
| CVE-2020-3147 | Alta (7.5) | 2.3% | — | 30 ene 2020 | A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper… |
| CVE-2019-12718 | Media (6.1) | 0.80% | — | 16 oct 2019 | A vulnerability in the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the… |
| CVE-2019-12636 | Alta (8.8) | 0.65% | — | 16 oct 2019 | A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an… |
| CVE-2019-1943 | Media (6.1) | 9.7% | — | 17 jul 2019 | A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is… |
| CVE-2019-1892 | Alta (7.5) | 1.8% | — | 6 jul 2019 | A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a memory corruption on… |
| CVE-2019-1891 | Alta (7.5) | 1.8% | — | 6 jul 2019 | A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.… |
| CVE-2019-1814 | Alta (8.6) | 2.1% | — | 16 may 2019 | A vulnerability in the interactions between the DHCP and TFTP features for Cisco Small Business 300 Series (Sx300) Managed Switches could allow an unauthenticated, remote attacker to cause the device to become low on… |
| CVE-2019-1806 | Alta (7.7) | 2.0% | — | 15 may 2019 | A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches… |
| CVE-2019-1859 | Alta (7.2) | 0.84% | — | 3 may 2019 | A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow an attacker to bypass client-side certificate authentication and revert to password authentication.… |
| CVE-2018-15439 | Crítica (9.8) | 50% | — | 8 nov 2018 | A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under… |
| CVE-2018-0465 | Media (6.1) | 0.80% | — | 5 oct 2018 | A vulnerability in the web-based management interface of Cisco Small Business 300 Series Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of… |
| CVE-2018-0408 | Media (5.4) | 0.68% | — | 1 ago 2018 | A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack… |
| CVE-2018-0407 | Media (5.4) | 0.68% | — | 1 ago 2018 | A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack… |
| CVE-2017-12308 | Media (6.1) | 0.83% | — | 18 ene 2018 | A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack against a user of the web interface of… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.