So I have been patching all my switches and most of them have come back clean. We have both SG300 and SG500. I have 3 that came up with the following issues:
OpenSSH issues that are supposed to be vendor fix but I have patched.
HTTP negative Content-Length Buffer overflow
Do I need to patch the MIB stuff?