CVE Feed

    Dashboard / CVE / CVE-2022-31734

    CVE-2022-31734

    Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerability regarding error page generation. An arbitrary script may be executed on the web browser of the user who is using the product. The affected firmware is prior to 12.2(50)SY released in 2011, and Cisco Catalyst 2940 Series Switches have been retired since January 2015

    Published:Jun 20, 2022
    Last Modified:Nov 21, 2024
    EPS:Jun 20, 2022
    EPSS Score:0.00779
    CVSS Score:6.1

    Affected Products

    Vendor
    Cisco
    Product
    Ws-c2940-8tf-s
    Vendor
    Cisco
    Product
    Ws-c2940-8tf-s Firmware
    Vendor
    Cisco
    Product
    Ws-c2940-8tt-s
    Vendor
    Cisco
    Product
    Ws-c2940-8tt-s Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High