VendorsCiscosg350x-48pany version
Vulnerabilities

Cisco SG350X-48P any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2020-3297
Cisco Small Business Smart and Managed Switches Session Management Vulnerability
Published 2020-07-02 · Modified
10.0EPSS 0.030
CVE-2018-15439
Cisco Small Business Switches Privileged Access Vulnerability
Published 2018-11-08 · Modified
9.8EPSS 0.497
CVE-2023-20189
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.111
CVE-2023-20161
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.103
CVE-2023-20159
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.103
CVE-2023-20160
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.103
CVE-2023-20162
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2023-20156
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2023-20157
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2023-20158
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
9.8EPSS 0.012
CVE-2020-3363
Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability
Published 2020-08-17 · Modified
8.6EPSS 0.018
CVE-2023-20024
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Published 2023-05-18 · Modified
8.6EPSS 0.013
CVE-2021-34739
Cisco Small Business Series Switches Session Credentials Replay Vulnerability
Published 2021-11-04 · Modified
8.1EPSS 0.017
CVE-2019-15993
Cisco Small Business Switches Information Disclosure Vulnerability
Published 2020-09-23 · Modified
7.51 PoCEPSS 0.103
CVE-2019-1859
Cisco Small Business Switches Secure Shell Certificate Authentication Bypass Vulnerability
Published 2019-05-03 · Modified
7.2EPSS 0.008
CVE-2024-20263
A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series Managed Switches could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected device. This vulnerability is due to incorrect processing of ACLs on a stacked configuration when either the primary or backup switches experience a full stack reload or power cycle. An attacker could exploit this vulnerability by sending crafted traffic through an affected device. A successful exploit could allow the attacker to bypass configured ACLs, causing traffic to be dropped or forwarded in an unexpected manner. The attacker does not have control over the conditions that result in the device being in the vulnerable state. Note: In the vulnerable state, the ACL would be correctly applied on the primary devices but could be incorrectly applied to the backup devices.
Published 2024-01-26 · Modified
7.2EPSS 0.005
CVE-2017-6720
A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition. The vulnerability is due to improper processing of SSH connections. An attacker could exploit this vulnerability by logging in to an affected switch via SSH and sending a malicious SSH message. This vulnerability affects the following Cisco products when SSH is enabled: Small Business 300 Series Managed Switches, Small Business 500 Series Stackable Managed Switches, 350 Series Managed Switches, 350X Series Stackable Managed Switches, 550X Series Stackable Managed Switches, ESW2 Series Advanced Switches. Cisco Bug IDs: CSCvb48377.
Published 2017-09-21 · Modified
6.8EPSS 0.014
CVE-2017-12307
A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by convincing a user to follow a malicious link or by intercepting and injecting code into a user request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information. This vulnerability affects the following Cisco Small Business 300 and 500 Series Managed Switches: Cisco Small Business 300 Series Managed Switches, Cisco Small Business 500 Series Stackable Managed Switches, Cisco 350 Series Managed Switches, Cisco 350X Series Stackable Managed Switches, Cisco 550X Series Stackable Managed Switches, Cisco ESW2 Series Advanced Switches. Cisco Bug IDs: CSCvg24637.
Published 2018-01-18 · Modified
6.1EPSS 0.009
CVE-2017-12308
A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by convincing a user to follow a malicious link or by intercepting a user request and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information. This vulnerability affects the following Cisco Small Business 300 and 500 Series Managed Switches: Cisco 350 Series Managed Switches, Cisco 350X Series Stackable Managed Switches, Cisco 550X Series Stackable Managed Switches, Cisco ESW2 Series Advanced Switches, Cisco Small Business 300 Series Managed Switches, Cisco Small Business 500 Series Stackable Managed Switches. Cisco Bug IDs: CSCvg29980.
Published 2018-01-18 · Modified
6.1EPSS 0.008
CVE-2020-3496
Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability
Published 2020-08-26 · Modified
5.3EPSS 0.017