cbcvebase.

Cisco Data Center Network Manager vulnerabilities

67 known vulnerabilities affecting cisco/data_center_network_manager.

Total CVEs
67
CISA KEV
1
actively exploited
Public exploits
12
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH26MEDIUM34

Vulnerabilities

Page 2 of 4
CVE-2020-3538P3HIGHCVSS 8.1fixed in 11.4\(1\)2024-11-18
CVE-2020-3538 [HIGH] CWE-20 CVE-2020-3538: A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Soft A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient path restriction enforcement. An attacker could exploit this vulnerability by sending crafted HTTP requests to
nvd
CVE-2019-15981P3HIGHCVSS 7.2fixed in 11.3\(1\)2020-01-06
CVE-2019-15981 [HIGH] CWE-22 CVE-2019-15981: Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM applicati
nvd
CVE-2019-15982P3HIGHCVSS 7.2fixed in 11.3\(1\)2020-01-06
CVE-2019-15982 [HIGH] CWE-22 CVE-2019-15982: Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM applicati
nvd
CVE-2019-15985P3HIGHCVSS 7.2fixed in 11.3\(1\)2020-01-06
CVE-2019-15985 [HIGH] CWE-89 CVE-2019-15985: Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DC Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulner
nvd
CVE-2021-1272P3HIGHCVSS 8.8fixed in 11.5\(1\)2021-01-20
CVE-2021-1272 [HIGH] CWE-918 CVE-2021-1272: A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. This vulnerability is due to insufficient validation of parameters in a specific HTTP request by an attacker.
nvd
CVE-2017-12343P3HIGHCVSS 8.8v10.3\(1\)s32017-11-30
CVE-2017-12343 [HIGH] CWE-79 CVE-2017-12343: Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote a Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a cross-site scripting (XSS) attack against a user of the affected software.
nvd
CVE-2020-3519P3HIGHCVSS 8.1fixed in 11.4\(1\)2020-08-26
CVE-2020-3519 [HIGH] CWE-20 CVE-2020-3519: A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software c A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker could exploit this vulnerability by sending a crafted
nvd
CVE-2021-1248P3HIGHCVSS 7.2fixed in 11.5\(1\)2021-01-20
CVE-2021-1248 [HIGH] CWE-89 CVE-2021-1248: Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) c Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2018-0210P3HIGHCVSS 8.8v10.4\(1.128\)v10.4\(2\)2018-03-08
CVE-2018-0210 [HIGH] CWE-352 CVE-2018-0210: A vulnerability in the web-based management interface of Cisco Data Center Network Manager could all A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections on the web-based management interface of an affecte
nvd
CVE-2020-3114P3HIGHCVSS 8.8fixed in 11.3\(1\)2020-02-19
CVE-2020-3114 [HIGH] CWE-352 CVE-2020-3114: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker
nvd
CVE-2020-3384P3HIGHCVSS 8.2fixed in 11.4\(1\)2020-07-31
CVE-2020-3384 [HIGH] CWE-184 CVE-2020-3384: A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could all A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system with the privileges of the logged-in user. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker could exploi
nvd
CVE-2018-0440P3HIGHCVSS 7.2fixed in 11.0\(1\)2018-10-05
CVE-2018-0440 [HIGH] CWE-264 CVE-2018-0440: A vulnerability in the web interface of Cisco Data Center Network Manager could allow an authenticat A vulnerability in the web interface of Cisco Data Center Network Manager could allow an authenticated application administrator to execute commands on the underlying operating system with root-level privileges. The vulnerability is due to incomplete input validation of user input within an HTTP request. An attacker could exploit this vulnerability by a
nvd
CVE-2020-3380P3HIGHCVSS 7.8fixed in 11.4\(1\)2020-07-16
CVE-2020-3380 [HIGH] CWE-88 CVE-2020-3380: A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient restrictions during the execution of an affected CLI command. An attacker could exploit this vulnerabi
nvd
CVE-2020-3521P3MEDIUMCVSS 6.5fixed in 11.4\(1\)2020-08-26
CVE-2020-3521 [MEDIUM] CWE-20 CVE-2020-3521: A vulnerability in a specific REST API of Cisco Data Center Network Manager (DCNM) Software could al A vulnerability in a specific REST API of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker with a low-privileged account could exploit this vulner
nvd
CVE-2021-1133P3HIGHCVSS 7.3fixed in 11.4\(1\)2021-01-20
CVE-2021-1133 [HIGH] CWE-184 CVE-2021-1133: Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3522P3MEDIUMCVSS 6.3fixed in 11.4\(1\)2020-08-26
CVE-2020-3522 [MEDIUM] CWE-284 CVE-2020-3522: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) So A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to bypass authorization on an affected device and access sensitive information that is related to the device. The vulnerability exists because the affected software allows users to access resources th
nvd
CVE-2020-3462P3MEDIUMCVSS 6.3fixed in 11.4\(1\)2020-07-31
CVE-2020-3462 [MEDIUM] CWE-89 CVE-2020-3462: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the applic
nvd
CVE-2011-4650P3HIGHCVSS 7.5v5.2\(1\)2017-08-07
CVE-2011-4650 [HIGH] CWE-399 CVE-2011-4650: Cisco Data Center Network Manager is affected by Excessive Logging During a TCP Flood on Java Ports. Cisco Data Center Network Manager is affected by Excessive Logging During a TCP Flood on Java Ports. If the size of server.log becomes very big because of too much logging by the DCNM server, then the CPU utilization increases. Known Affected Releases: 5.2(1). Known Fixed Releases: 6.0(0)SL1(0.14) 5.2(2.73)S0. Product identification: CSCtt15295.
nvd
CVE-2021-1269P3MEDIUMCVSS 6.3fixed in 11.5\(1\)2021-01-20
CVE-2021-1269 [MEDIUM] CWE-863 CVE-2021-1269: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1270P3MEDIUMCVSS 6.5fixed in 11.5\(1\)2021-01-20
CVE-2021-1270 [MEDIUM] CWE-863 CVE-2021-1270: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
Cisco Data Center Network Manager vulnerabilities | cvebase