cbcvebase.

Cisco Data Center Network Manager vulnerabilities

74 known vulnerabilities affecting cisco/cisco_data_center_network_manager.

Total CVEs
74
CISA KEV
0
Public exploits
11
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH32MEDIUM36

Vulnerabilities

Page 4 of 4
CVE-2021-1253P4MEDIUMCVSS 5.4vn/a2021-01-20
CVE-2021-1253 [MEDIUM] CWE-20 CVE-2021-1253: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
nvd
CVE-2021-1250P4MEDIUMCVSS 5.4vn/a2021-01-20
CVE-2021-1250 [MEDIUM] CWE-20 CVE-2021-1250: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
nvd
CVE-2021-1249P4MEDIUMCVSS 5.4vn/a2021-01-20
CVE-2021-1249 [MEDIUM] CWE-20 CVE-2021-1249: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
nvd
CVE-2020-3113P4MEDIUMCVSS 5.4≥ unspecified, < n/a2020-02-19
CVE-2020-3113 [MEDIUM] CWE-79 CVE-2020-3113: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interf
nvd
CVE-2020-3518P4MEDIUMCVSS 5.4vn/a2020-08-26
CVE-2020-3518 [MEDIUM] CWE-79 CVE-2020-3518: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) So A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of the affected software. The vulnerability exists because the web-based management interface does not properly validate u
nvd
CVE-2020-3523P4MEDIUMCVSS 5.4vn/a2020-08-26
CVE-2020-3523 [MEDIUM] CWE-79 CVE-2020-3523: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) So A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An at
nvd
CVE-2020-3520P4MEDIUMCVSS 5.5vn/a2020-08-26
CVE-2020-3520 [MEDIUM] CWE-200 CVE-2020-3520: A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, l A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, local attacker to obtain confidential information from an affected device. The vulnerability is due to insufficient protection of confidential information on an affected device. An attacker at any privilege level could exploit this vulnerability by acces
nvd
CVE-2021-1283P4MEDIUMCVSS 5.5vn/a2021-01-20
CVE-2021-1283 [MEDIUM] CWE-789 CVE-2021-1283: A vulnerability in the logging subsystem of Cisco Data Center Network Manager (DCNM) could allow an A vulnerability in the logging subsystem of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to view sensitive information in a system log file that should be restricted. The vulnerability exists because sensitive information is not properly masked before it is written to system log files. An attacker could exploit
nvd
CVE-2021-1135P4MEDIUMCVSS 4.3vn/a2021-01-20
CVE-2021-1135 [MEDIUM] CWE-184 CVE-2021-1135: Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3439P4MEDIUMCVSS 4.8vn/a2020-08-26
CVE-2020-3439 [MEDIUM] CWE-79 CVE-2020-3439: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) So A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploi
nvd
CVE-2020-3349P4MEDIUMCVSS 4.8vn/a2020-07-16
CVE-2020-3349 [MEDIUM] CWE-79 CVE-2020-3349: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based man
nvd
CVE-2020-3348P4MEDIUMCVSS 4.8vn/a2020-07-16
CVE-2020-3348 [MEDIUM] CWE-79 CVE-2020-3348: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based man
nvd
CVE-2020-3354P4MEDIUMCVSS 4.8vn/a2020-06-18
CVE-2020-3354 [MEDIUM] CWE-79 CVE-2020-3354: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient input validation by the web-based management interface. A
nvd
CVE-2020-3355P4MEDIUMCVSS 4.8vn/a2020-06-18
CVE-2020-3355 [MEDIUM] CWE-79 CVE-2020-3355: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient input validation by the web-based management interface. A
nvd
Cisco Data Center Network Manager vulnerabilities | cvebase