Improper Authentication in Cisco Small Business 220 Series Smart Switches - CVE-2021-1542
Published: June 16, 2021
Vulnerability identifier: #VU54173
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1542
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to usage of weak sessionidentifiers. A remote unauthenticated attacker can guess active session identifier, bypass authentication process and gain unauthorized access to the application.
Affected software
Cisco Small Business 220 Series Smart Switches
How to mitigate CVE-2021-1542
Install updates from vendor's website.
Cisco Small Business 220 Series Smart Switches - update to 1.2.0.6