Cisco
Cisco Sg500-28mpp Firmware: vulnerabilities and CVEs
Cisco Sg500-28mpp Firmware has 29 published vulnerabilities, 0 of them in the last 12 months. 10 are rated critical and 0 are listed by CISA as actively exploited.
CVEs29
Last 12 months0
Critical10
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20188 | Medium (4.8) | 0.48% | — | Jun 28, 2023 | A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches… |
| CVE-2023-20189 | Critical (9.8) | 11% | — | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20162 | Critical (9.8) | 1.2% | — | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20161 | Critical (9.8) | 10% | — | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20160 | Critical (9.8) | 10% | — | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20159 | Critical (9.8) | 10% | — | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20158 | Critical (9.8) | 1.2% | — | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20157 | Critical (9.8) | 1.2% | — | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20156 | Critical (9.8) | 1.2% | — | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2023-20024 | High (7.5) | 1.3% | — | May 18, 2023 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary… |
| CVE-2021-27853 | Medium (4.7) | 0.81% | — | Sep 27, 2022 | Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers. |
| CVE-2021-40127 | Medium (5.3) | 1.3% | — | Nov 4, 2021 | A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches… |
| CVE-2021-34739 | High (8.1) | 1.7% | — | Nov 4, 2021 | A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized… |
| CVE-2019-15993 | Medium (5.3) | 10% | — | Sep 23, 2020 | A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper… |
| CVE-2020-3496 | Medium (5.3) | 1.7% | — | Aug 26, 2020 | A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.… |
| CVE-2020-3363 | High (8.6) | 1.8% | — | Aug 17, 2020 | A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.… |
| CVE-2020-3297 | Critical (9.8) | 3.0% | — | Jul 2, 2020 | A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to defeat authentication protections and gain… |
| CVE-2020-3147 | High (7.5) | 2.3% | — | Jan 30, 2020 | A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper… |
| CVE-2019-12718 | Medium (6.1) | 0.80% | — | Oct 16, 2019 | A vulnerability in the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the… |
| CVE-2019-12636 | High (8.8) | 0.65% | — | Oct 16, 2019 | A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an… |
| CVE-2019-1943 | Medium (6.1) | 9.7% | — | Jul 17, 2019 | A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is… |
| CVE-2019-1892 | High (7.5) | 1.8% | — | Jul 6, 2019 | A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a memory corruption on… |
| CVE-2019-1891 | High (7.5) | 1.8% | — | Jul 6, 2019 | A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.… |
| CVE-2019-1806 | High (7.7) | 2.0% | — | May 15, 2019 | A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches… |
| CVE-2019-1859 | High (7.2) | 0.84% | — | May 3, 2019 | A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow an attacker to bypass client-side certificate authentication and revert to password authentication.… |
| CVE-2018-15439 | Critical (9.8) | 50% | — | Nov 8, 2018 | A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under… |
| CVE-2017-12308 | Medium (6.1) | 0.83% | — | Jan 18, 2018 | A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack against a user of the web interface of… |
| CVE-2017-12307 | Medium (6.1) | 0.87% | — | Jan 18, 2018 | A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web… |
| CVE-2017-6720 | Medium (6.5) | 1.4% | — | Sep 21, 2017 | A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.