Severity
8.8HIGH
EPSS
0.5%
top 33.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateMay 24

Description

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to obtain sensitive information from or inject arbitrary commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages7 packages

🔴Vulnerability Details

2
GHSA
GHSA-jwh8-8mm7-rv2p: Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could a2022-05-24
CVEList
Cisco Small Business 100, 300, and 500 Series Wireless Access Points Vulnerabilities2021-05-06

💥Exploits & PoCs

1
Nuclei
Auerswald COMfortel 1400/2600/3600 IP - Authentication Bypass

📋Vendor Advisories

1
Cisco
Cisco Small Business 100, 300, and 500 Series Wireless Access Points Vulnerabilities2021-05-05
CVE-2021-1400 (HIGH CVSS 8.8) | Multiple vulnerabilities in the web | cvebase.io