Cisco Data Center Network Manager vulnerabilities
74 known vulnerabilities affecting cisco/cisco_data_center_network_manager.
Total CVEs
74
CISA KEV
0
Public exploits
11
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH32MEDIUM36
Vulnerabilities
Page 3 of 4
CVE-2024-20441P3MEDIUMCVSS 6.5v12.1(1)v12.0.1a+9 more2024-10-02
CVE-2024-20441 [MEDIUM] CWE-285 CVE-2024-20441: A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-priv
A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device.
This vulnerability is due to insufficient authorization controls on the affected REST API endpoint. An attacker could exploit this vulnerability by sending crafted API requ
nvd
CVE-2021-1133P3HIGHCVSS 7.3vn/a2021-01-20
CVE-2021-1133 [HIGH] CWE-184 CVE-2021-1133: Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3539P3MEDIUMCVSS 6.3vN/A2024-11-18
CVE-2020-3539 [MEDIUM] CWE-285 CVE-2020-3539: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization.
The vulnerability is due to a failure to limit access to resources that are intended for users with Administrator privileges. An attacker could ex
nvd
CVE-2020-3522P3MEDIUMCVSS 6.3vn/a2020-08-26
CVE-2020-3522 [MEDIUM] CWE-284 CVE-2020-3522: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) So
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to bypass authorization on an affected device and access sensitive information that is related to the device. The vulnerability exists because the affected software allows users to access resources th
nvd
CVE-2020-3462P3MEDIUMCVSS 6.3vn/a2020-07-31
CVE-2020-3462 [MEDIUM] CWE-89 CVE-2020-3462: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the applic
nvd
CVE-2021-1269P3MEDIUMCVSS 6.3vn/a2021-01-20
CVE-2021-1269 [MEDIUM] CWE-863 CVE-2021-1269: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1270P3MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1270 [MEDIUM] CWE-863 CVE-2021-1270: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1277P3MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1277 [MEDIUM] CWE-295 CVE-2021-1277: Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoo
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate validation when establishing HTTPS requests with the affected device. For
nvd
CVE-2021-1276P3MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1276 [MEDIUM] CWE-295 CVE-2021-1276: Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoo
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate validation when establishing HTTPS requests with the affected device. For
nvd
CVE-2024-20477P3MEDIUMCVSS 5.4v12.1(1)v12.0.1a+9 more2024-10-02
CVE-2024-20477 [MEDIUM] CWE-862 CVE-2024-20477: A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-priv
A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to upload or delete files on an affected device.
This vulnerability exists because of missing authorization controls on the affected REST API endpoint. An attacker could exploit this vulnerability by sending crafted API reques
nvd
CVE-2024-20438P3MEDIUMCVSS 5.4v12.1(1)v12.0.1a+9 more2024-10-02
CVE-2024-20438 [MEDIUM] CWE-693 CVE-2024-20438: A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged
A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected device.
This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending crafted API requests to an affecte
nvd
CVE-2025-20347P3MEDIUMCVSS 5.4v11.2(1)v7.0(2)+38 more2025-08-27
CVE-2025-20347 [MEDIUM] CWE-693 CVE-2025-20347: A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric
A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to view sensitive information or upload and modify files on an affected device.
This vulnerability exists because of missing authorization controls on some REST API endpoi
nvd
CVE-2024-20444P4MEDIUMCVSS 5.5v11.2(1)v7.0(2)+36 more2024-10-02
CVE-2024-20444 [MEDIUM] CWE-88 CVE-2024-20444: A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Networ
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device.
This vulnerability is due to insufficient validation of command arguments. An attacker coul
nvd
CVE-2019-15983P4MEDIUMCVSS 4.9≥ unspecified, < n/a2020-01-06
CVE-2019-15983 [MEDIUM] CWE-611 CVE-2019-15983: A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authentic
A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrative privileges on the DCNM application. The vulnerability exists because the SOAP API impro
nvd
CVE-2020-3461P4MEDIUMCVSS 5.3vn/a2020-07-31
CVE-2020-3461 [MEDIUM] CWE-306 CVE-2020-3461: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. The vulnerability is due to missing authentication on a specific part of the web-based management interface. An attacker could exploit this vulnera
nvd
CVE-2021-1255P4MEDIUMCVSS 5.4vn/a2021-01-20
CVE-2021-1255 [MEDIUM] CWE-184 CVE-2021-1255: Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3460P4MEDIUMCVSS 6.1vn/a2020-07-31
CVE-2020-3460 [MEDIUM] CWE-79 CVE-2020-3460: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker
nvd
CVE-2021-1286P4MEDIUMCVSS 6.1vn/a2021-01-20
CVE-2021-1286 [MEDIUM] CWE-20 CVE-2021-1286: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
nvd
CVE-2018-0450P4MEDIUMCVSS 6.1vn/a2018-10-05
CVE-2018-0450 [MEDIUM] CWE-79 CVE-2018-0450: A vulnerability in the web-based management interface of Cisco Data Center Network Manager could all
A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the management interface on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management
nvd
CVE-2020-3356P4MEDIUMCVSS 6.1vn/a2020-06-18
CVE-2020-3356 [MEDIUM] CWE-79 CVE-2020-3356: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this
nvd