VendorsCiscosg300-52_firmwareall versions
Vulnerabilities

Cisco SG300-52 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

32CVEs
CVE-2020-3297
Cisco Small Business Smart and Managed Switches Session Management Vulnerability
Published 2020-07-02 · Modified
10.0EPSS 0.030
CVE-2018-15439
Cisco Small Business Switches Privileged Access Vulnerability
Published 2018-11-08 · Modified
9.8EPSS 0.497
CVE-2023-20189
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.111
CVE-2023-20161
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.103
CVE-2023-20160
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.103
CVE-2023-20159
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.103
CVE-2023-20162
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2023-20158
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2023-20157
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2023-20156
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2019-12636
Cisco Small Business Smart and Managed Switches Cross-Site Request Forgery Vulnerability
Published 2019-10-16 · Modified
8.8EPSS 0.006
CVE-2020-3147
Cisco Small Business Switches Denial of Service Vulnerability
Published 2020-01-29 · Modified
8.6EPSS 0.023
CVE-2019-1814
Cisco Small Business 300 Series Managed Switches DHCP Denial of Service Vulnerability
Published 2019-05-15 · Modified
8.6EPSS 0.021
CVE-2020-3363
Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability
Published 2020-08-17 · Modified
8.6EPSS 0.018
CVE-2023-20024
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
8.6EPSS 0.013
CVE-2021-34739
Cisco Small Business Series Switches Session Credentials Replay Vulnerability
Published 2021-11-04 · Modified
8.1EPSS 0.017
CVE-2019-1806
Cisco Small Business Series Switches Simple Network Management Protocol Denial of Service Vulnerability
Published 2019-05-15 · Modified
7.7EPSS 0.020
CVE-2019-15993
Cisco Small Business Switches Information Disclosure Vulnerability
Published 2020-09-23 · Modified
7.51 PoCEPSS 0.103
CVE-2019-1891
Cisco Small Business Series Switches HTTP Denial of Service Vulnerability
Published 2019-07-06 · Modified
7.5EPSS 0.018
CVE-2019-1892
Cisco Small Business Series Switches Memory Corruption Vulnerability
Published 2019-07-06 · Modified
7.5EPSS 0.018
CVE-2019-1859
Cisco Small Business Switches Secure Shell Certificate Authentication Bypass Vulnerability
Published 2019-05-03 · Modified
7.2EPSS 0.008
CVE-2017-6720
A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition. The vulnerability is due to improper processing of SSH connections. An attacker could exploit this vulnerability by logging in to an affected switch via SSH and sending a malicious SSH message. This vulnerability affects the following Cisco products when SSH is enabled: Small Business 300 Series Managed Switches, Small Business 500 Series Stackable Managed Switches, 350 Series Managed Switches, 350X Series Stackable Managed Switches, 550X Series Stackable Managed Switches, ESW2 Series Advanced Switches. Cisco Bug IDs: CSCvb48377.
Published 2017-09-21 · Modified
6.8EPSS 0.014
CVE-2019-1943
Cisco Small Business Series Switches Open Redirect Vulnerability
Published 2019-07-17 · Modified
6.11 PoCEPSS 0.097
CVE-2017-12307
A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by convincing a user to follow a malicious link or by intercepting and injecting code into a user request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information. This vulnerability affects the following Cisco Small Business 300 and 500 Series Managed Switches: Cisco Small Business 300 Series Managed Switches, Cisco Small Business 500 Series Stackable Managed Switches, Cisco 350 Series Managed Switches, Cisco 350X Series Stackable Managed Switches, Cisco 550X Series Stackable Managed Switches, Cisco ESW2 Series Advanced Switches. Cisco Bug IDs: CSCvg24637.
Published 2018-01-18 · Modified
6.1EPSS 0.009
CVE-2017-12308
A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by convincing a user to follow a malicious link or by intercepting a user request and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information. This vulnerability affects the following Cisco Small Business 300 and 500 Series Managed Switches: Cisco 350 Series Managed Switches, Cisco 350X Series Stackable Managed Switches, Cisco 550X Series Stackable Managed Switches, Cisco ESW2 Series Advanced Switches, Cisco Small Business 300 Series Managed Switches, Cisco Small Business 500 Series Stackable Managed Switches. Cisco Bug IDs: CSCvg29980.
Published 2018-01-18 · Modified
6.1EPSS 0.008
CVE-2019-12718
Cisco Small Business Smart and Managed Switches Cross-Site Scripting Vulnerability
Published 2019-10-16 · Modified
6.1EPSS 0.008
CVE-2018-0465
Cisco Small Business 300 Series Managed Switches Cross-Site Scripting Vulnerability
Published 2018-10-05 · Modified
6.1EPSS 0.008
CVE-2018-0408
A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvi87330.
Published 2018-08-01 · Modified
5.4EPSS 0.007
CVE-2018-0407
A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvi87326.
Published 2018-08-01 · Modified
5.4EPSS 0.007
CVE-2020-3496
Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability
Published 2020-08-26 · Modified
5.3EPSS 0.017
CVE-2021-40127
Cisco Small Business 200, 300, and 500 Series Switches Web-Based Management Interface Denial of Service Vulnerability
Published 2021-11-04 · Modified
5.3EPSS 0.013
CVE-2023-20188
A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to view a page containing malicious HTML or script content. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker would need to have valid credentials to access the web-based management interface of the affected device. Cisco has not released software updates to address this vulnerability.
Published 2023-06-28 · Modified
4.8EPSS 0.005