Cisco Network Level Service vulnerabilities
7 known vulnerabilities affecting cisco/network_level_service.
Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-3567MEDIUMCVSS 6.5v1.8\(0.142\)v1.9\(0.63\)2020-10-08
CVE-2020-3567 [MEDIUM] CWE-20 CVE-2020-3567: A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an
A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU utilization to increase to 100 percent, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of requests sent to the REST API. An atta
nvd
CVE-2019-15973MEDIUMCVSS 6.1v1.7\(0.186\)2019-11-26
CVE-2019-15973 [MEDIUM] CWE-79 CVE-2019-15973: A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) cou
A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected application. The vulnerability is due to insufficient validation of user-supplied input by the web-based manageme
nvd
CVE-2019-1976CRITICALCVSS 9.8v1.6\(0.369\)2019-09-05
CVE-2019-1976 [CRITICAL] CWE-200 CVE-2019-1976: A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Di
A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper access restrictions on the web-based management interface. An attacker could exploit this vulnerability by sen
nvd
CVE-2019-1821CRITICALCVSS 9.8PoCv3.0\(0.0.83b\)2019-05-16
CVE-2019-1821 [HIGH] CWE-20 CVE-2019-1821: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
nvd
CVE-2019-1823HIGHCVSS 7.2v3.0\(0.0.83b\)2019-05-16
CVE-2019-1823 [HIGH] CWE-20 CVE-2019-1823: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. A
nvd
CVE-2019-1825HIGHCVSS 8.1v3.0\(0.0.83b\)2019-05-16
CVE-2019-1825 [HIGH] CWE-89 CVE-2019-1825: A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco E
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly validates user-supplied input in SQL queries. An attacker could exploit this
nvd
CVE-2018-0446HIGHCVSS 8.8v1.5\(0.128\)2018-10-05
CVE-2018-0446 [HIGH] CWE-352 CVE-2018-0446: A vulnerability in the web-based management interface of Cisco Industrial Network Director could all
A vulnerability in the web-based management interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface. An attacker
nvd