Cisco Network Services Orchestrator vulnerabilities

10 known vulnerabilities affecting cisco/cisco_network_services_orchestrator.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2021-1132HIGHCVSS 7.5v5.3.1v5.4.0.1+2 more2024-11-18
CVE-2021-1132 [MEDIUM] CWE-35 CVE-2021-1132: A vulnerability in the API subsystem and in the web-management interface of Cisco Network Servi A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access sensitive data. This vulnerability exists because the web-management interface and certain HTTP-based APIs do not properly validate user-supplied input. An attacker could exploit
cvelistv5nvd
CVE-2022-20655HIGHCVSS 8.8vN/A2024-11-15
CVE-2022-20655 [HIGH] CWE-78 CVE-2022-20655: A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an au A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient validation of a process argument on an affected device. An attacker could exploit this vulnerability by injecting commands during the execution of
cvelistv5nvd
CVE-2024-20381HIGHCVSS 8.8v5.4.1v5.3.1+161 more2024-09-11
CVE-2024-20381 [HIGH] CWE-285 CVE-2024-20381: A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) a A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device. This
cvelistv5nvd
CVE-2024-20326HIGHCVSS 7.8vN/A2024-05-16
CVE-2024-20326 [HIGH] CWE-78 CVE-2024-20326: A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could al A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI commands are used. An attacker could exp
cvelistv5nvd
CVE-2024-20389HIGHCVSS 7.8v6.0.112024-05-16
CVE-2024-20389 [HIGH] CWE-266 CVE-2024-20389: A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could al A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI commands are used. An attacker could ex
cvelistv5nvd
CVE-2024-20366HIGHCVSS 7.8v5.4v5.5+146 more2024-05-15
CVE-2024-20366 [HIGH] CWE-73 CVE-2024-20366: A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability exists because a user-controlled search path is used to locate executable files. An attacker
cvelistv5nvd
CVE-2024-20369MEDIUMCVSS 6.1v5.4v5.5+91 more2024-05-15
CVE-2024-20369 [MEDIUM] CWE-601 CVE-2024-20369: A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrat A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading
cvelistv5nvd
CVE-2023-20040MEDIUMCVSS 5.5v4.7.32023-01-20
CVE-2023-20040 [MEDIUM] CWE-23 CVE-2023-20040: A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an a A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vulnerability, the attacker must be a member of the admin group. This vulnerability exists because user-supplied in
cvelistv5nvd
CVE-2020-3362MEDIUMCVSS 4.7vn/a2020-06-18
CVE-2020-3362 [MEDIUM] CWE-200 CVE-2020-3362: A vulnerability in the CLI of Cisco Network Services Orchestrator (NSO) could allow an authenticated A vulnerability in the CLI of Cisco Network Services Orchestrator (NSO) could allow an authenticated, local attacker to access confidential information on an affected device. The vulnerability is due to a timing issue in the processing of CLI commands. An attacker could exploit this vulnerability by executing a specific sequence of commands on the CLI
cvelistv5nvd
CVE-2018-0463HIGHCVSS 7.5vn/a2018-10-05
CVE-2018-0463 [HIGH] CWE-264 CVE-2018-0463: A vulnerability in the Cisco Network Plug and Play server component of Cisco Network Services Orches A vulnerability in the Cisco Network Plug and Play server component of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to gain unauthorized access to configuration data that is stored on an affected NSO system. The vulnerability exists because the Network Plug and Play component performs incomplete validation wh
cvelistv5nvd