Lucene search

K

Small Business 220 Series Smart Plus Switches Security Vulnerabilities

cve
cve

CVE-2016-1470

Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuz76230.

8.8CVSS

9AI Score

0.003EPSS

2016-09-02 12:59 AM
20
cve
cve

CVE-2016-1471

Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz76232.

6.1CVSS

6AI Score

0.002EPSS

2016-09-02 12:59 AM
24
cve
cve

CVE-2016-1472

The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz76238.

7.5CVSS

7.3AI Score

0.003EPSS

2016-09-02 12:59 AM
22
cve
cve

CVE-2016-1473

Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP objects by leveraging knowledge of this community, aka Bug ID CSCuz76216.

9.8CVSS

8.5AI Score

0.006EPSS

2016-09-02 12:59 AM
23