cbcvebase.

Cisco Data Center Network Manager vulnerabilities

74 known vulnerabilities affecting cisco/cisco_data_center_network_manager.

Total CVEs
74
CISA KEV
0
Public exploits
11
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH32MEDIUM36

Vulnerabilities

Page 1 of 4
CVE-2019-15975P1CRITICALCVSS 9.8PoC≥ unspecified, < n/a2020-01-06
CVE-2019-15975 [CRITICAL] CWE-798 CVE-2019-15975: Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory
nvd
CVE-2019-15976P1CRITICALCVSS 9.8PoC≥ unspecified, < n/a2020-01-06
CVE-2019-15976 [CRITICAL] CWE-798 CVE-2019-15976: Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory
nvd
CVE-2019-1619P1CRITICALCVSS 9.8PoC≥ unspecified, < 11.1(1)2019-06-27
CVE-2019-1619 [CRITICAL] CWE-284 CVE-2019-1619: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper session management on affected DCNM software. An attacker c
nvd
CVE-2019-1620P1CRITICALCVSS 9.8PoC≥ unspecified, < 11.2(1)2019-06-27
CVE-2019-1620 [CRITICAL] CWE-264 CVE-2019-1620: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due to incorrect permission settings in affected DCNM software. An attacker could exploit this vulnerability by uploading specially cra
nvd
CVE-2019-15977P2HIGHCVSS 7.5PoC≥ unspecified, < n/a2020-01-06
CVE-2019-15977 [HIGH] CWE-798 CVE-2019-15977: Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2019-15984P2HIGHCVSS 7.2PoC≥ unspecified, < n/a2020-01-06
CVE-2019-15984 [HIGH] CWE-89 CVE-2019-15984: Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DC Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulner
nvd
CVE-2019-1622P2MEDIUMCVSS 5.3PoC≥ unspecified, < 11.2(1)2019-06-27
CVE-2019-1622 [MEDIUM] CWE-284 CVE-2019-1622: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls for certain URLs on affected DCNM software. An attacker could exploit this vulnerability by con
nvd
CVE-2019-1621P2HIGHCVSS 7.5PoC≥ unspecified, < 11.2(1)2019-06-27
CVE-2019-1621 [HIGH] CWE-264 CVE-2019-1621: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device. The vulnerability is due to incorrect permissions settings on affected DCNM software. An attacker could exploit this vulnerability by connecting to the
nvd
CVE-2019-15978P2HIGHCVSS 7.2PoC≥ unspecified, < n/a2020-01-06
CVE-2019-15978 [HIGH] CWE-78 CVE-2019-15978: Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DC Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For more information about these vulnerabilities, see the Details section of th
nvd
CVE-2019-15979P3HIGHCVSS 7.2PoC≥ unspecified, < n/a2020-01-06
CVE-2019-15979 [HIGH] CWE-78 CVE-2019-15979: Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DC Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For more information about these vulnerabilities, see the Details section of th
nvd
CVE-2020-3382P2CRITICALCVSS 9.8vn/a2020-07-31
CVE-2020-3382 [CRITICAL] CWE-798 CVE-2020-3382: A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthent A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists because different installations share a static encryption key. An attacker could exploit this
nvd
CVE-2019-15980P2HIGHCVSS 7.2≥ unspecified, < n/a2020-01-06
CVE-2019-15980 [HIGH] CWE-22 CVE-2019-15980: Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM applicati
nvd
CVE-2019-15999P3MEDIUMCVSS 6.3PoC≥ unspecified, < n/a2020-01-06
CVE-2019-15999 [MEDIUM] CWE-284 CVE-2019-15999: A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could all A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. The vulnerability is due to an incorrect configuration of the authentication settings on the JBoss EAP. An
nvd
CVE-2020-3376P2CRITICALCVSS 9.8vn/a2020-07-31
CVE-2020-3376 [CRITICAL] CWE-306 CVE-2020-3376: A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions on an affected device. The vulnerability is due to a failure in the software to perform proper authentication. An attacker could exploit this vulnerability
nvd
CVE-2020-3383P2HIGHCVSS 8.8vn/a2020-07-31
CVE-2020-3383 [HIGH] CWE-20 CVE-2020-3383: A vulnerability in the archive utility of Cisco Data Center Network Manager (DCNM) could allow an au A vulnerability in the archive utility of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to a lack of proper input validation of paths that are embedded within archive files. An attacker could exploit this vulnerability by sendin
nvd
CVE-2024-20432P2HIGHCVSS 8.8v12.1(1)v12.0.1a+9 more2024-10-02
CVE-2024-20432 [HIGH] CWE-77 CVE-2024-20432: A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could a A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to improper user authorization and insufficient validation of command arguments. An attacker could exploit
nvd
CVE-2024-20449P2HIGHCVSS 8.8v12.1(1)v12.0.1a+9 more2024-10-02
CVE-2024-20449 [HIGH] CWE-23 CVE-2024-20449: A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remo A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected device. This vulnerability is due to improper path validation. An attacker could exploit this vulnerability by using the Secure Copy Protocol (SCP) to upload malicious code to an a
nvd
CVE-2024-20536P2HIGHCVSS 8.8v12.1.2ev12.1.2p+1 more2024-11-06
CVE-2024-20536 [HIGH] CWE-89 CVE-2024-20536: A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard F A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could explo
nvd
CVE-2020-3386P2HIGHCVSS 8.8vn/a2020-07-31
CVE-2020-3386 [HIGH] CWE-285 CVE-2020-3386: A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device. The vulnerability is due to insufficient authorization of certain API functions. An attacker could exploit this vulnerability by sending
nvd
CVE-2021-1247P2HIGHCVSS 8.8vn/a2021-01-20
CVE-2021-1247 [HIGH] CWE-89 CVE-2021-1247: Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) c Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
Cisco Data Center Network Manager vulnerabilities | cvebase