...
This product includes Third-party Software that is affected by the vulnerabilities identified by the following Common Vulnerability and Exposures (CVE) IDs: CVE-2007-2768 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2768 CVE-2018-15473 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15473 CVE-2018-15919 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15919 CVE-2018-20685 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20685 CVE-2019-6109 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6109 CVE-2019-6110 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6110 CVE-2019-6111 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6111 CVE-2020-14145 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14145 CVE-2021-28041 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28041 CVE-2021-41617 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41617 After analysis, Cisco has decided against performing additional actions on this product due to one of the following reasons: - The product is no longer maintained, having reached End of Software Maintenance. - The product is still being maintained, but a business decision was made not to upgrade the vulnerable product. - The product uses the affected third-party component in such a way as to not be affected by these vulnerabilities.
Device with default configuration.
Not available or not applicable.
Additional details about the vulnerabilities listed above can be found at https://www.cve.org/. PSIRT Evaluation: The Cisco PSIRT has assigned this bug the following CVSS version 3.0 score. The Base CVSS score as of the time of evaluation is: 7.5 https://tools.cisco.com/security/center/cvssCalculator.x?version=3.0&vector=CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C CVE ID CVE-2007-2768, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-28041, CVE-2021-41617 have been assigned to document this issue. Additional information on Cisco's security vulnerability policy can be found at the following URL: http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html