Cisco Data Center Network Manager vulnerabilities
67 known vulnerabilities affecting cisco/data_center_network_manager.
Total CVEs
67
CISA KEV
1
actively exploited
Public exploits
12
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH26MEDIUM34
Vulnerabilities
Page 3 of 4
CVE-2021-1277P3MEDIUMCVSS 6.5fixed in 11.5\(1\)2021-01-20
CVE-2021-1277 [MEDIUM] CWE-295 CVE-2021-1277: Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoo
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate validation when establishing HTTPS requests with the affected device. For
nvd
CVE-2021-1276P3MEDIUMCVSS 6.5fixed in 11.5\(1\)2021-01-20
CVE-2021-1276 [MEDIUM] CWE-295 CVE-2021-1276: Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoo
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests. These vulnerabilities are due to insufficient certificate validation when establishing HTTPS requests with the affected device. For
nvd
CVE-2019-15983P4MEDIUMCVSS 4.9fixed in 11.3\(1\)2020-01-06
CVE-2019-15983 [MEDIUM] CWE-611 CVE-2019-15983: A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authentic
A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrative privileges on the DCNM application. The vulnerability exists because the SOAP API impro
nvd
CVE-2020-3461P4MEDIUMCVSS 5.3fixed in 11.4\(1\)2020-07-31
CVE-2020-3461 [MEDIUM] CWE-306 CVE-2020-3461: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. The vulnerability is due to missing authentication on a specific part of the web-based management interface. An attacker could exploit this vulnera
nvd
CVE-2021-1255P4MEDIUMCVSS 5.4fixed in 11.4\(1\)2021-01-20
CVE-2021-1255 [MEDIUM] CWE-184 CVE-2021-1255: Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3460P4MEDIUMCVSS 6.1fixed in 11.4\(1\)2020-07-31
CVE-2020-3460 [MEDIUM] CWE-79 CVE-2020-3460: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker
nvd
CVE-2021-1286P4MEDIUMCVSS 6.1fixed in 11.5\(1\)2021-01-20
CVE-2021-1286 [MEDIUM] CWE-20 CVE-2021-1286: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
nvd
CVE-2017-12344P4MEDIUMCVSS 6.1v10.2\(1\)2017-11-30
CVE-2017-12344 [MEDIUM] CWE-79 CVE-2017-12344: Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote a
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a cross-site scripting (XSS) attack against a user of the affected software
nvd
CVE-2018-0450P4MEDIUMCVSS 6.1v10.4\(2\)2018-10-05
CVE-2018-0450 [MEDIUM] CWE-79 CVE-2018-0450: A vulnerability in the web-based management interface of Cisco Data Center Network Manager could all
A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the management interface on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management
nvd
CVE-2017-12346P4MEDIUMCVSS 6.1v10.2\(1\)2017-11-30
CVE-2017-12346 [MEDIUM] CWE-79 CVE-2017-12346: Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote a
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a cross-site scripting (XSS) attack against a user of the affected software
nvd
CVE-2017-12347P4MEDIUMCVSS 6.1v10.2\(1\)2017-11-30
CVE-2017-12347 [MEDIUM] CWE-79 CVE-2017-12347: Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote a
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a cross-site scripting (XSS) attack against a user of the affected software
nvd
CVE-2020-3356P4MEDIUMCVSS 6.1≤ 11.3\(1\)2020-06-18
CVE-2020-3356 [MEDIUM] CWE-79 CVE-2020-3356: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this
nvd
CVE-2021-1253P4MEDIUMCVSS 5.4fixed in 11.5\(1\)2021-01-20
CVE-2021-1253 [MEDIUM] CWE-20 CVE-2021-1253: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
nvd
CVE-2021-1250P4MEDIUMCVSS 5.4fixed in 11.5\(1\)2021-01-20
CVE-2021-1250 [MEDIUM] CWE-20 CVE-2021-1250: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
nvd
CVE-2021-1249P4MEDIUMCVSS 5.4fixed in 11.5\(1\)2021-01-20
CVE-2021-1249 [MEDIUM] CWE-20 CVE-2021-1249: Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Detai
nvd
CVE-2020-3113P4MEDIUMCVSS 5.4fixed in 11.3\(1\)2020-02-19
CVE-2020-3113 [MEDIUM] CWE-79 CVE-2020-3113: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interf
nvd
CVE-2020-3518P4MEDIUMCVSS 5.4fixed in 11.4\(1\)2020-08-26
CVE-2020-3518 [MEDIUM] CWE-79 CVE-2020-3518: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) So
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of the affected software. The vulnerability exists because the web-based management interface does not properly validate u
nvd
CVE-2020-3523P4MEDIUMCVSS 5.4fixed in 11.4\(1\)2020-08-26
CVE-2020-3523 [MEDIUM] CWE-79 CVE-2020-3523: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) So
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An at
nvd
CVE-2020-3520P4MEDIUMCVSS 5.5fixed in 11.4\(1\)2020-08-26
CVE-2020-3520 [MEDIUM] CWE-200 CVE-2020-3520: A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, l
A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, local attacker to obtain confidential information from an affected device. The vulnerability is due to insufficient protection of confidential information on an affected device. An attacker at any privilege level could exploit this vulnerability by acces
nvd
CVE-2021-1283P4MEDIUMCVSS 5.5fixed in 11.5\(1\)2021-01-20
CVE-2021-1283 [MEDIUM] CWE-789 CVE-2021-1283: A vulnerability in the logging subsystem of Cisco Data Center Network Manager (DCNM) could allow an
A vulnerability in the logging subsystem of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to view sensitive information in a system log file that should be restricted. The vulnerability exists because sensitive information is not properly masked before it is written to system log files. An attacker could exploit
nvd