CVE-2021-34739
A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface of an affected device. This vulnerability is due to insufficient expiration of session credentials. An attacker could exploit this vulnerability by conducting a man-in-the-middle attack against an affected device to intercept valid session credentials and then replaying the intercepted credentials toward the same device at a later time. A successful exploit could allow the attacker to access the web-based management interface with administrator privileges.
EPSS 0.50% · 66.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | sf250x-48_firmware | 0 |
| cisco | sg200-50p_firmware | |
| cisco | cbs350-16p-e-2g_firmware | 0 |
| cisco | cbs350-24ngp-4x_firmware | 0 |
| cisco | cbs350-16xts_firmware | 0 |
| cisco | sf302-08pp_firmware | 1.4.11.02 |
| cisco | sg200-10fp_firmware | |
| cisco | sf250-26p_firmware | 0 |
| cisco | sg550xg-8f8t_firmware | 0 |
| cisco | cbs250-16t-2g_firmware | 0 |
| cisco | cbs350-24p-4g_firmware | 0 |
| cisco | sf350-8pd_firmware | 0 |
| cisco | sx550x-52_firmware | 0 |
| cisco | sf352-08mp_firmware | 0 |
| cisco | sf250-08_firmware | 0 |
| cisco | sf350-28mp_firmware | 0 |
| cisco | sf300-24mp_firmware | 1.4.11.02 |
| cisco | sf300-48pp_firmware | 1.4.11.02 |
| cisco | cbs350-8mgp-2x_firmware | 0 |
| cisco | cbs350-8mp-2x_firmware | 0 |
…and 190 more
Exploit Intelligence
Timeline
- Nov 4, 2021 CVE Published
- Nov 5, 2021 EPSS Score
- Dec 31, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 21, 2022 EPSS Score
- Jun 16, 2022 EPSS Score
- Aug 12, 2022 EPSS Score
- Oct 6, 2022 EPSS Score
- Dec 1, 2022 EPSS Score
- Jan 26, 2023 EPSS Score
References
- 20211103 Cisco Small Business Series Switches Session Credentials Replay Vulnerability vendor-advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cps-static-key-JmS92hNv advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-dos-JOm9ETfO advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catpon-multivulns-CE3DSYGr advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-34739 advisory