CVE-2021-34744

MEDIUM

Cisco Business 220 Series - Privilege Escalation

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the Details section of this advisory.

References (1)

Core 1

Scores

CVSS v3 4.9
EPSS 0.0030
EPSS Percentile 52.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-540 CWE-798
Status published
Products (16)
cisco/business_220-16p-2g_firmware < 1.2.0.6
cisco/business_220-16t-2g_firmware < 1.2.0.6
cisco/business_220-24fp-4g_firmware < 1.2.0.6
cisco/business_220-24fp-4x_firmware < 1.2.0.6
cisco/business_220-24p-4g_firmware < 1.2.0.6
cisco/business_220-24p-4x_firmware < 1.2.0.6
cisco/business_220-24t-4g_firmware < 1.2.0.6
cisco/business_220-24t-4x_firmware < 1.2.0.6
cisco/business_220-48fp-4x_firmware < 1.2.0.6
cisco/business_220-48p-4g_firmware < 1.2.0.6
... and 6 more
Published Oct 06, 2021
Tracked Since Feb 18, 2026