Cisco Data Center Network Manager vulnerabilities
67 known vulnerabilities affecting cisco/data_center_network_manager.
Total CVEs
67
CISA KEV
1
actively exploited
Public exploits
12
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH26MEDIUM34
Vulnerabilities
Page 1 of 4
CVE-2021-44228P1CRITICALCVSS 10.0KEVPoCRansomwarefixed in 11.3\(1\)v11.3\(1\)2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd
CVE-2019-15975P1CRITICALCVSS 9.8PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15975 [CRITICAL] CWE-798 CVE-2019-15975: Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory
nvd
CVE-2019-15976P1CRITICALCVSS 9.8PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15976 [CRITICAL] CWE-798 CVE-2019-15976: Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory
nvd
CVE-2019-1619P1CRITICALCVSS 9.8PoCv10.4\(2\)2019-06-27
CVE-2019-1619 [CRITICAL] CWE-284 CVE-2019-1619: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper session management on affected DCNM software. An attacker c
nvd
CVE-2019-1620P1CRITICALCVSS 9.8PoCv11.0\(1\)2019-06-27
CVE-2019-1620 [CRITICAL] CWE-264 CVE-2019-1620: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due to incorrect permission settings in affected DCNM software. An attacker could exploit this vulnerability by uploading specially cra
nvd
CVE-2019-15977P2HIGHCVSS 7.5PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15977 [HIGH] CWE-798 CVE-2019-15977: Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2019-15984P2HIGHCVSS 7.2PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15984 [HIGH] CWE-89 CVE-2019-15984: Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DC
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulner
nvd
CVE-2019-1622P2MEDIUMCVSS 5.3PoCv11.0\(1\)2019-06-27
CVE-2019-1622 [MEDIUM] CWE-284 CVE-2019-1622: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls for certain URLs on affected DCNM software. An attacker could exploit this vulnerability by con
nvd
CVE-2019-1621P2HIGHCVSS 7.5PoCv11.0\(1\)2019-06-27
CVE-2019-1621 [HIGH] CWE-264 CVE-2019-1621: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device. The vulnerability is due to incorrect permissions settings on affected DCNM software. An attacker could exploit this vulnerability by connecting to the
nvd
CVE-2019-15978P2HIGHCVSS 7.2PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15978 [HIGH] CWE-78 CVE-2019-15978: Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DC
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For more information about these vulnerabilities, see the Details section of th
nvd
CVE-2019-15979P3HIGHCVSS 7.2PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15979 [HIGH] CWE-78 CVE-2019-15979: Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DC
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For more information about these vulnerabilities, see the Details section of th
nvd
CVE-2020-3382P2CRITICALCVSS 9.8fixed in 11.4\(1\)2020-07-31
CVE-2020-3382 [CRITICAL] CWE-798 CVE-2020-3382: A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthent
A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists because different installations share a static encryption key. An attacker could exploit this
nvd
CVE-2019-15980P2HIGHCVSS 7.2fixed in 11.3\(1\)2020-01-06
CVE-2019-15980 [HIGH] CWE-22 CVE-2019-15980: Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of
Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM applicati
nvd
CVE-2019-15999P3MEDIUMCVSS 6.3PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15999 [MEDIUM] CWE-284 CVE-2019-15999: A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could all
A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. The vulnerability is due to an incorrect configuration of the authentication settings on the JBoss EAP. An
nvd
CVE-2020-3376P2CRITICALCVSS 9.8v11.0\(1\)v11.1\(1\)+2 more2020-07-31
CVE-2020-3376 [CRITICAL] CWE-306 CVE-2020-3376: A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions on an affected device. The vulnerability is due to a failure in the software to perform proper authentication. An attacker could exploit this vulnerability
nvd
CVE-2020-3383P2HIGHCVSS 8.8fixed in 11.4\(1\)2020-07-31
CVE-2020-3383 [HIGH] CWE-20 CVE-2020-3383: A vulnerability in the archive utility of Cisco Data Center Network Manager (DCNM) could allow an au
A vulnerability in the archive utility of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to a lack of proper input validation of paths that are embedded within archive files. An attacker could exploit this vulnerability by sendin
nvd
CVE-2020-3386P2HIGHCVSS 8.8fixed in 11.4\(1\)2020-07-31
CVE-2020-3386 [HIGH] CWE-285 CVE-2020-3386: A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device. The vulnerability is due to insufficient authorization of certain API functions. An attacker could exploit this vulnerability by sending
nvd
CVE-2021-1247P2HIGHCVSS 8.8fixed in 11.5\(1\)2021-01-20
CVE-2021-1247 [HIGH] CWE-89 CVE-2021-1247: Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) c
Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3112P3HIGHCVSS 8.8fixed in 11.3\(1\)2020-02-19
CVE-2020-3112 [HIGH] CWE-264 CVE-2020-3112: A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to elevate privileges on the application. The vulnerability is due to insufficient access control validation. An attacker could exploit this vulnerability by authenticating with a low-privilege account and sending a crafted r
nvd
CVE-2020-3377P3HIGHCVSS 8.8v11.0\(1\)v11.1\(1\)+2 more2020-07-31
CVE-2020-3377 [HIGH] CWE-78 CVE-2020-3377: A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted arguments to a specific
nvd
1 / 4Next →