Cisco Dna Center vulnerabilities
2 known vulnerabilities affecting cisco/dna_center.
Total CVEs
2
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2023-20223HIGHCVSS 8.2fixed in 2.3.5.42023-09-27
CVE-2023-20223 [HIGH] CWE-284 CVE-2023-20223: A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modi
A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an internal service on an affected device.
This vulnerability is due to insufficient access control enforcement on API requests. An attacker could exploit this vulnerability by sending a crafted API request to an
nvd
CVE-2021-44228CRITICALCVSS 10.0KEVPoCfixed in 2.1.2.8≥ 2.2.2.0, < 2.2.2.8+2 more2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd