Cisco Data Center Network Manager vulnerabilities
75 known vulnerabilities affecting cisco/cisco_data_center_network_manager.
Total CVEs
75
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH33MEDIUM36
Vulnerabilities
Page 2 of 4
CVE-2021-1269MEDIUMCVSS 6.3vn/a2021-01-20
CVE-2021-1269 [MEDIUM] CWE-863 CVE-2021-1269: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2021-1135MEDIUMCVSS 4.3vn/a2021-01-20
CVE-2021-1135 [MEDIUM] CWE-184 CVE-2021-1135: Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2021-1276MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1276 [MEDIUM] CWE-295 CVE-2021-1276: Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoo
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate validation when establishing HTTPS requests with the affected device. For
cvelistv5nvd
CVE-2021-1253MEDIUMCVSS 5.4vn/a2021-01-20
CVE-2021-1253 [MEDIUM] CWE-20 CVE-2021-1253: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
cvelistv5nvd
CVE-2021-1283MEDIUMCVSS 5.5vn/a2021-01-20
CVE-2021-1283 [MEDIUM] CWE-789 CVE-2021-1283: A vulnerability in the logging subsystem of Cisco Data Center Network Manager (DCNM) could allow an
A vulnerability in the logging subsystem of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to view sensitive information in a system log file that should be restricted. The vulnerability exists because sensitive information is not properly masked before it is written to system log files. An attacker could exploit
cvelistv5nvd
CVE-2021-1270MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1270 [MEDIUM] CWE-863 CVE-2021-1270: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2021-1249MEDIUMCVSS 5.4vn/a2021-01-20
CVE-2021-1249 [MEDIUM] CWE-20 CVE-2021-1249: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
cvelistv5nvd
CVE-2021-1286MEDIUMCVSS 6.1vn/a2021-01-20
CVE-2021-1286 [MEDIUM] CWE-20 CVE-2021-1286: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
cvelistv5nvd
CVE-2021-1250MEDIUMCVSS 5.4vn/a2021-01-20
CVE-2021-1250 [MEDIUM] CWE-20 CVE-2021-1250: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
cvelistv5nvd
CVE-2021-1255MEDIUMCVSS 5.4vn/a2021-01-20
CVE-2021-1255 [MEDIUM] CWE-184 CVE-2021-1255: Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2020-3519HIGHCVSS 8.1vn/a2020-08-26
CVE-2020-3519 [HIGH] CWE-20 CVE-2020-3519: A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software c
A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker could exploit this vulnerability by sending a crafted
cvelistv5nvd
CVE-2020-3518MEDIUMCVSS 5.4vn/a2020-08-26
CVE-2020-3518 [MEDIUM] CWE-79 CVE-2020-3518: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) So
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of the affected software. The vulnerability exists because the web-based management interface does not properly validate u
cvelistv5nvd
CVE-2020-3522MEDIUMCVSS 6.3vn/a2020-08-26
CVE-2020-3522 [MEDIUM] CWE-284 CVE-2020-3522: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) So
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to bypass authorization on an affected device and access sensitive information that is related to the device. The vulnerability exists because the affected software allows users to access resources th
cvelistv5nvd
CVE-2020-3523MEDIUMCVSS 5.4vn/a2020-08-26
CVE-2020-3523 [MEDIUM] CWE-79 CVE-2020-3523: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) So
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An at
cvelistv5nvd
CVE-2020-3521MEDIUMCVSS 6.5vn/a2020-08-26
CVE-2020-3521 [MEDIUM] CWE-20 CVE-2020-3521: A vulnerability in a specific REST API of Cisco Data Center Network Manager (DCNM) Software could al
A vulnerability in a specific REST API of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker with a low-privileged account could exploit this vulner
cvelistv5nvd
CVE-2020-3439MEDIUMCVSS 4.8vn/a2020-08-26
CVE-2020-3439 [MEDIUM] CWE-79 CVE-2020-3439: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) So
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploi
cvelistv5nvd
CVE-2020-3520MEDIUMCVSS 5.5vn/a2020-08-26
CVE-2020-3520 [MEDIUM] CWE-200 CVE-2020-3520: A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, l
A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, local attacker to obtain confidential information from an affected device. The vulnerability is due to insufficient protection of confidential information on an affected device. An attacker at any privilege level could exploit this vulnerability by acces
cvelistv5nvd
CVE-2020-3382CRITICALCVSS 9.8vn/a2020-07-31
CVE-2020-3382 [CRITICAL] CWE-798 CVE-2020-3382: A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthent
A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists because different installations share a static encryption key. An attacker could exploit this
cvelistv5nvd
CVE-2020-3376CRITICALCVSS 9.8vn/a2020-07-31
CVE-2020-3376 [CRITICAL] CWE-306 CVE-2020-3376: A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions on an affected device. The vulnerability is due to a failure in the software to perform proper authentication. An attacker could exploit this vulnerability
cvelistv5nvd
CVE-2020-3377HIGHCVSS 8.8vn/a2020-07-31
CVE-2020-3377 [HIGH] CWE-78 CVE-2020-3377: A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted arguments to a specific
cvelistv5nvd