Vulnerabilities > Cisco > Sg220 52 Firmware > 1.0.0.19

DATE CVE VULNERABILITY TITLE RISK
2019-08-07 CVE-2019-1914 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to perform a command injection attack.
network
low complexity
cisco CWE-20
critical
9.0
2019-08-07 CVE-2019-1913 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating system.
network
low complexity
cisco CWE-119
critical
10.0
2019-08-07 CVE-2019-1912 Incorrect Authorization vulnerability in Cisco products
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files.
network
low complexity
cisco CWE-863
6.4