Vulnerabilities > Cisco > Sg220 28Mp Firmware > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-08-07 CVE-2019-1912 Incorrect Authorization vulnerability in Cisco products
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files.
network
low complexity
cisco CWE-863
critical
9.1
2019-08-07 CVE-2019-1913 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating system.
network
low complexity
cisco CWE-119
critical
9.8