Cisco Digital Network Architecture Center vulnerabilities
33 known vulnerabilities affecting cisco/cisco_digital_network_architecture_center.
Total CVEs
33
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH14MEDIUM16
Vulnerabilities
Page 2 of 2
CVE-2021-1303HIGHCVSS 8.8vn/a2021-01-20
CVE-2021-1303 [HIGH] CWE-266 CVE-2021-1303: A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remot
A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execute unauthorized commands on an affected device. The vulnerability is due to improper enforcement of actions for assigned user roles. An attacker could exploit this vulnerability by authenticating as a user with an Observer role and exec
nvd
CVE-2021-1265MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1265 [MEDIUM] CWE-312 CVE-2021-1265: A vulnerability in the configuration archive functionality of Cisco DNA Center could allow any privi
A vulnerability in the configuration archive functionality of Cisco DNA Center could allow any privilege-level authenticated, remote attacker to obtain the full unmasked running configuration of managed devices. The vulnerability is due to the configuration archives files being stored in clear text, which can be retrieved by various API calls. An atta
nvd
CVE-2021-1130MEDIUMCVSS 4.8vn/a2021-01-13
CVE-2021-1130 [MEDIUM] CWE-79 CVE-2021-1130: A vulnerability in the web-based management interface of Cisco DNA Center software could allow an au
A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An atta
nvd
CVE-2020-3466MEDIUMCVSS 6.1vn/a2020-08-26
CVE-2020-3466 [MEDIUM] CWE-79 CVE-2020-3466: Multiple vulnerabilities in the web-based management interface of Cisco DNA Center software could al
Multiple vulnerabilities in the web-based management interface of Cisco DNA Center software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerabilities exist because the web-based management interface on an affected device does not properly val
nvd
CVE-2020-3411HIGHCVSS 7.5vn/a2020-08-17
CVE-2020-3411 [HIGH] CWE-200 CVE-2020-3411: A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access t
A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to improper handling of authentication tokens by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A success
nvd
CVE-2020-3391MEDIUMCVSS 6.5vn/a2020-07-02
CVE-2020-3391 [MEDIUM] CWE-200 CVE-2020-3391: A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, rem
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencrypted credentials on an affected device. An attacker could exploit this vulnerability by viewing the network device configuration and
nvd
CVE-2020-3281HIGHCVSS 8.8vn/a2020-06-03
CVE-2020-3281 [HIGH] CWE-532 CVE-2020-3281: A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center co
A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs and obtaining cre
nvd
CVE-2019-15253MEDIUMCVSS 4.8PoCv1.3.0.6v1.3.1.42020-02-05
CVE-2019-15253 [MEDIUM] CWE-79 CVE-2019-15253: A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Ce
A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied in
nvd
CVE-2019-1848CRITICALCVSS 9.3≥ unspecified, < 1.32019-06-20
CVE-2019-1848 [CRITICAL] CWE-668 CVE-2019-1848: A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, a
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports necessary for system operation. An attacker could exploit this vulnerability by connecting an unautho
nvd
CVE-2019-1841HIGHCVSS 8.1≥ unspecified, < DNAC1.2.52019-04-18
CVE-2019-1841 [HIGH] CWE-441 CVE-2019-1841: A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenti
A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending arbitrary HTTP requests to interna
nvd
CVE-2019-1707MEDIUMCVSS 5.4≥ unspecified, < 1.2.52019-03-11
CVE-2019-1707 [MEDIUM] CWE-79 CVE-2019-1707: A vulnerability in the web-based management interface of Cisco DNA Center could allow an authenticat
A vulnerability in the web-based management interface of Cisco DNA Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interfac
nvd
CVE-2018-15386CRITICALCVSS 9.8vn/a2018-10-05
CVE-2018-15386 [CRITICAL] CWE-16 CVE-2018-15386: A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, r
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and have direct unauthorized access to critical management functions. The vulnerability is due to an insecure default configuration of the affected system. An attacker could exploit this vulnerability by direct
nvd
CVE-2018-0448CRITICALCVSS 9.8vn/a2018-10-05
CVE-2018-0448 [CRITICAL] CWE-326 CVE-2018-0448: A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Cente
A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due to insufficient security restrictions for critical management functions. An attacker could
nvd
← Previous2 / 2