
CVE-2021-34739 – Cisco Small Business Series Switches Session Credentials Replay Vulnerability
https://notcve.org/view.php?id=CVE-2021-34739
04 Nov 2021 — A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface of an affected device. This vulnerability is due to insufficient expiration of session credentials. An attacker could exploit this vulnerability by conducting a man-in-the-middle attack against an affected device to intercept valid session credentials a... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-switches-tokens-UzwpR4e5 • CWE-613: Insufficient Session Expiration •

CVE-2020-3496 – Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability
https://notcve.org/view.php?id=CVE-2020-3496
26 Aug 2020 — A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet through an affected device. A successful exploit could allow the attacker to cause the switch management CLI to stop responding, resulti... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbss-ipv6-dos-tsgqbffW • CWE-20: Improper Input Validation •