VendorsCiscosf500-24mpany version
Vulnerabilities

Cisco SF500-24MP any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2023-20189
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.111
CVE-2023-20159
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.103
CVE-2023-20160
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.103
CVE-2023-20161
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.103
CVE-2023-20156
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2023-20157
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2023-20158
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2023-20162
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2023-20024
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
8.6EPSS 0.013
CVE-2021-34739
Cisco Small Business Series Switches Session Credentials Replay Vulnerability
Published 2021-11-04 · Modified
8.1EPSS 0.017
CVE-2019-1806
Cisco Small Business Series Switches Simple Network Management Protocol Denial of Service Vulnerability
Published 2019-05-15 · Modified
7.7EPSS 0.020
CVE-2018-0209
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device nay need to be manually reloaded to recover. The vulnerability is due to lack of proper input throttling of ingress SNMP traffic over an internal interface. An attacker could exploit this vulnerability by sending a crafted, heavy stream of SNMP traffic to the targeted device. An exploit could allow the attacker to cause the device to reload unexpectedly, causing a DoS condition. Cisco Bug IDs: CSCvg22135.
Published 2018-03-08 · Modified
7.7EPSS 0.016
CVE-2019-1891
Cisco Small Business Series Switches HTTP Denial of Service Vulnerability
Published 2019-07-06 · Modified
7.5EPSS 0.018
CVE-2019-1892
Cisco Small Business Series Switches Memory Corruption Vulnerability
Published 2019-07-06 · Modified
7.5EPSS 0.018
CVE-2021-40127
Cisco Small Business 200, 300, and 500 Series Switches Web-Based Management Interface Denial of Service Vulnerability
Published 2021-11-04 · Modified
5.3EPSS 0.013
CVE-2023-20188
A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to view a page containing malicious HTML or script content. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker would need to have valid credentials to access the web-based management interface of the affected device. Cisco has not released software updates to address this vulnerability.
Published 2023-06-28 · Modified
4.8EPSS 0.005