imPC@ndo IT

Tracker / CVE-2021-34739

CVE-2021-34739

High 8.1

A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface of an affected device. This vulnerability is due to insufficient expiration of session credentials. An attacker could exploit this vulnerability by conducting a man-in-the-middle attack against an affected device to intercept valid session credentials and then replaying the intercepted credentials toward the same device at a later time. A successful exploit could allow the attacker to access the web-based management interface with administrator privileges.

Affected products and versions

cisco cbs250-16p-2g_firmware · … → 3.1
cisco cbs250-16t-2g_firmware · … → 3.1
cisco cbs250-24fp-4g_firmware · … → 3.1
cisco cbs250-24fp-4x_firmware · … → 3.1
cisco cbs250-24p-4g_firmware · … → 3.1
cisco cbs250-24p-4x_firmware · … → 3.1
cisco cbs250-24pp-4g_firmware · … → 3.1
cisco cbs250-24t-4g_firmware · … → 3.1
cisco cbs250-24t-4x_firmware · … → 3.1
cisco cbs250-48p-4g_firmware · … → 3.1
cisco cbs250-48p-4x_firmware · … → 3.1
cisco cbs250-48pp-4g_firmware · … → 3.1
cisco cbs250-48t-4g_firmware · … → 3.1
cisco cbs250-48t-4x_firmware · … → 3.1
cisco cbs250-8fp-e-2g_firmware · … → 3.1
cisco cbs250-8p-e-2g_firmware · … → 3.1
cisco cbs250-8pp-d_firmware · … → 3.1
cisco cbs250-8pp-e-2g_firmware · … → 3.1
cisco cbs250-8t-d_firmware · … → 3.1
cisco cbs250-8t-e-2g_firmware · … → 3.1
cisco cbs350-12np-4x_firmware · … → 3.1
cisco cbs350-12xs_firmware · … → 3.1
cisco cbs350-12xt_firmware · … → 3.1
cisco cbs350-16fp-2g_firmware · … → 3.1
cisco cbs350-16p-2g_firmware · … → 3.1
cisco cbs350-16p-e-2g_firmware · … → 3.1
cisco cbs350-16t-2g_firmware · … → 3.1
cisco cbs350-16t-e-2g_firmware · … → 3.1
cisco cbs350-16xts_firmware · … → 3.1
cisco cbs350-24fp-4g_firmware · … → 3.1
cisco cbs350-24fp-4x_firmware · … → 3.1
cisco cbs350-24mgp-4x_firmware · … → 3.1
cisco cbs350-24ngp-4x_firmware · … → 3.1
cisco cbs350-24p-4g_firmware · … → 3.1
cisco cbs350-24p-4x_firmware · … → 3.1
cisco cbs350-24s-4g_firmware · … → 3.1
cisco cbs350-24t-4g_firmware · … → 3.1
cisco cbs350-24t-4x_firmware · … → 3.1
cisco cbs350-24xs_firmware · … → 3.1
cisco cbs350-24xt_firmware · … → 3.1
cisco cbs350-24xts_firmware · … → 3.1
cisco cbs350-48fp-4g_firmware · … → 3.1
cisco cbs350-48fp-4x_firmware · … → 3.1
cisco cbs350-48ngp-4x_firmware · … → 3.1
cisco cbs350-48p-4g_firmware · … → 3.1
cisco cbs350-48p-4x_firmware · … → 3.1
cisco cbs350-48t-4g_firmware · … → 3.1
cisco cbs350-48t-4x_firmware · … → 3.1
cisco cbs350-48xt-4x_firmware · … → 3.1
cisco cbs350-8fp-2g_firmware · … → 3.1
cisco cbs350-8fp-e-2g_firmware · … → 3.1
cisco cbs350-8mgp-2x_firmware · … → 3.1
cisco cbs350-8mp-2x_firmware · … → 3.1
cisco cbs350-8p-2g_firmware · … → 3.1
cisco cbs350-8p-e-2g_firmware · … → 3.1
cisco cbs350-8s-e-2g_firmware · … → 3.1
cisco cbs350-8t-e-2g_firmware · … → 3.1
cisco cbs350-8xt_firmware · … → 3.1
cisco esw2-350g-52_firmware · … → 2.5
cisco esw2-350g-52dc_firmware · … → 2.5

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References