Cisco Catalyst Center vulnerabilities
24 known vulnerabilities affecting cisco/catalyst_center.
Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM13
Vulnerabilities
Page 2 of 2
CVE-2024-20333P4MEDIUMCVSS 4.3fixed in 2.3.5.42024-03-27
CVE-2024-20333 [MEDIUM] CWE-285 CVE-2024-20333: A vulnerability in the web-based management interface of Cisco Catalyst Center, formerly Cisco DNA C
A vulnerability in the web-based management interface of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to change specific data within the interface on an affected device.
This vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by sending a cra
nvd
CVE-2021-34782P4MEDIUMCVSS 4.3fixed in 2.2.2.5≥ 2.2.3.0, < 2.2.3.32021-10-06
CVE-2021-34782 [MEDIUM] CWE-202 CVE-2021-34782: A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attac
A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on API endpoints. An attacker could exploit the vulnerability by sending a sp
nvd
CVE-2021-1130P4MEDIUMCVSS 4.8fixed in 2.2.1.02021-01-13
CVE-2021-1130 [MEDIUM] CWE-79 CVE-2021-1130: A vulnerability in the web-based management interface of Cisco DNA Center software could allow an au
A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An atta
nvd
CVE-2022-20630P4MEDIUMCVSS 4.4≥ 2.1.2.0, < 2.2.2.8≥ 2.2.3.0, < 2.2.3.42022-02-10
CVE-2022-20630 [MEDIUM] CWE-200 CVE-2022-20630: A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to
A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive information in clear text. This vulnerability is due to the unsecured logging of sensitive information on an affected system. An attacker with administrative privileges could exploit this vulnerability by accessing the audit logs throu
nvd
← Previous2 / 2