Cisco Security Manager vulnerabilities
28 known vulnerabilities affecting cisco/security_manager.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7MEDIUM21
Vulnerabilities
Page 1 of 2
CVE-2020-27131P1CRITICALCVSS 9.8≤ 4.222020-11-17
CVE-2020-27131 [CRITICAL] CWE-20 CVE-2020-27131: Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit these vulnera
nvd
CVE-2019-12630P1CRITICALCVSS 9.8fixed in 4.182019-10-02
CVE-2019-12630 [CRITICAL] CWE-20 CVE-2019-12630: A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an u
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a mal
nvd
CVE-2020-27130P2CRITICALCVSS 9.1≤ 4.212020-11-17
CVE-2020-27130 [CRITICAL] CWE-35 CVE-2020-27130: A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain ac
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to an affected device. An attacker could exploit this vulnerability by sending a crafted request to the affected
nvd
CVE-2020-27125P2CRITICALCVSS 9.8≤ 4.212020-11-17
CVE-2020-27125 [CRITICAL] CWE-20 CVE-2020-27125: A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by viewing source code. A successful exploit could allow the
nvd
CVE-2010-3036P2CRITICALCVSS 10.0v3.0.2v3.22010-10-29
CVE-2010-3036 [CRITICAL] CWE-119 CVE-2010-3036: Multiple buffer overflows in the authentication functionality in the web-server module in Cisco Cisc
Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.
nvd
CVE-2009-1161P3CRITICALCVSS 10.0v3.0v3.1+1 more2009-05-21
CVE-2009-1161 [CRITICAL] CWE-22 CVE-2009-1161: Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0
Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows remote attackers to access arbitrar
nvd
CVE-2019-1903P3CRITICALCVSS 9.1v4.142019-06-20
CVE-2019-1903 [CRITICAL] CWE-611 CVE-2019-1903: A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability by sending malicious requests to a targeted system that contain referenc
nvd
CVE-2014-3326P3MEDIUMCVSS 6.5v4.5v4.62014-07-26
CVE-2014-3326 [MEDIUM] CWE-89 CVE-2014-3326: SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote
SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCup26957.
nvd
CVE-2008-3820P4MEDIUMCVSS 6.8v3.1v3.1.1+2 more2009-01-22
CVE-2008-3820 [MEDIUM] CVE-2008-3820: Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes
Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these ports.
nvd
CVE-2014-3267P4MEDIUMCVSS 6.8≤ 4.6v4.0+6 more2014-05-26
CVE-2014-3267 [MEDIUM] CWE-352 CVE-2014-3267: Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 a
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make unspecified changes, aka Bug ID CSCuo46427.
nvd
CVE-2018-0223P4MEDIUMCVSS 6.1v4.9\(0\)qa992018-03-08
CVE-2018-0223 [MEDIUM] CWE-79 CVE-2018-0223: A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager co
A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management inter
nvd
CVE-2022-20635P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20635 [MEDIUM] CWE-79 CVE-2022-20635: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2022-20647P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20647 [MEDIUM] CWE-79 CVE-2022-20647: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2022-20639P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20639 [MEDIUM] CWE-79 CVE-2022-20639: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2022-20645P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20645 [MEDIUM] CWE-79 CVE-2022-20645: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2022-20642P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20642 [MEDIUM] CWE-79 CVE-2022-20642: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2022-20636P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20636 [MEDIUM] CWE-79 CVE-2022-20636: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2022-20641P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20641 [MEDIUM] CWE-79 CVE-2022-20641: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2022-20638P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20638 [MEDIUM] CWE-79 CVE-2022-20638: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2022-20644P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20644 [MEDIUM] CWE-79 CVE-2022-20644: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
1 / 2Next →