Cisco Data Center Network Manager vulnerabilities
67 known vulnerabilities affecting cisco/data_center_network_manager.
Total CVEs
67
CISA KEV
1
actively exploited
Public exploits
10
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH26MEDIUM34
Vulnerabilities
Page 3 of 4
CVE-2020-3114HIGHCVSS 8.8fixed in 11.3\(1\)2020-02-19
CVE-2020-3114 [HIGH] CWE-352 CVE-2020-3114: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker
nvd
CVE-2020-3113MEDIUMCVSS 5.4fixed in 11.3\(1\)2020-02-19
CVE-2020-3113 [MEDIUM] CWE-79 CVE-2020-3113: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interf
nvd
CVE-2019-15975CRITICALCVSS 9.8PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15975 [CRITICAL] CWE-798 CVE-2019-15975: Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory
nvd
CVE-2019-15976CRITICALCVSS 9.8PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15976 [CRITICAL] CWE-798 CVE-2019-15976: Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory
nvd
CVE-2019-15985HIGHCVSS 7.2fixed in 11.3\(1\)2020-01-06
CVE-2019-15985 [HIGH] CWE-89 CVE-2019-15985: Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DC
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulner
nvd
CVE-2019-15984HIGHCVSS 7.2PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15984 [HIGH] CWE-89 CVE-2019-15984: Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DC
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulner
nvd
CVE-2019-15980HIGHCVSS 7.2fixed in 11.3\(1\)2020-01-06
CVE-2019-15980 [HIGH] CWE-22 CVE-2019-15980: Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of
Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM applicati
nvd
CVE-2019-15977HIGHCVSS 7.5PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15977 [HIGH] CWE-798 CVE-2019-15977: Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2019-15981HIGHCVSS 7.2fixed in 11.3\(1\)2020-01-06
CVE-2019-15981 [HIGH] CWE-22 CVE-2019-15981: Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of
Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM applicati
nvd
CVE-2019-15982HIGHCVSS 7.2fixed in 11.3\(1\)2020-01-06
CVE-2019-15982 [HIGH] CWE-22 CVE-2019-15982: Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of
Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM applicati
nvd
CVE-2019-15979HIGHCVSS 7.2fixed in 11.3\(1\)2020-01-06
CVE-2019-15979 [HIGH] CWE-78 CVE-2019-15979: Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DC
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For more information about these vulnerabilities, see the Details section of th
nvd
CVE-2019-15978HIGHCVSS 7.2PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15978 [HIGH] CWE-78 CVE-2019-15978: Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DC
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For more information about these vulnerabilities, see the Details section of th
nvd
CVE-2019-15999MEDIUMCVSS 6.3PoCfixed in 11.3\(1\)2020-01-06
CVE-2019-15999 [MEDIUM] CWE-284 CVE-2019-15999: A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could all
A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. The vulnerability is due to an incorrect configuration of the authentication settings on the JBoss EAP. An
nvd
CVE-2019-15983MEDIUMCVSS 4.9fixed in 11.3\(1\)2020-01-06
CVE-2019-15983 [MEDIUM] CWE-611 CVE-2019-15983: A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authentic
A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrative privileges on the DCNM application. The vulnerability exists because the SOAP API impro
nvd
CVE-2019-1620CRITICALCVSS 9.8PoCv11.0\(1\)2019-06-27
CVE-2019-1620 [CRITICAL] CWE-264 CVE-2019-1620: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due to incorrect permission settings in affected DCNM software. An attacker could exploit this vulnerability by uploading specially cra
nvd
CVE-2019-1619CRITICALCVSS 9.8PoCv10.4\(2\)2019-06-27
CVE-2019-1619 [CRITICAL] CWE-284 CVE-2019-1619: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper session management on affected DCNM software. An attacker c
nvd
CVE-2019-1621HIGHCVSS 7.5v11.0\(1\)2019-06-27
CVE-2019-1621 [HIGH] CWE-264 CVE-2019-1621: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device. The vulnerability is due to incorrect permissions settings on affected DCNM software. An attacker could exploit this vulnerability by connecting to the
nvd
CVE-2019-1622MEDIUMCVSS 5.3PoCv11.0\(1\)2019-06-27
CVE-2019-1622 [MEDIUM] CWE-284 CVE-2019-1622: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) co
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls for certain URLs on affected DCNM software. An attacker could exploit this vulnerability by con
nvd
CVE-2018-0440HIGHCVSS 7.2fixed in 11.0\(1\)2018-10-05
CVE-2018-0440 [HIGH] CWE-264 CVE-2018-0440: A vulnerability in the web interface of Cisco Data Center Network Manager could allow an authenticat
A vulnerability in the web interface of Cisco Data Center Network Manager could allow an authenticated application administrator to execute commands on the underlying operating system with root-level privileges. The vulnerability is due to incomplete input validation of user input within an HTTP request. An attacker could exploit this vulnerability by a
nvd
CVE-2018-0450MEDIUMCVSS 6.1v10.4\(2\)2018-10-05
CVE-2018-0450 [MEDIUM] CWE-79 CVE-2018-0450: A vulnerability in the web-based management interface of Cisco Data Center Network Manager could all
A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the management interface on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management
nvd