Cisco Security Manager vulnerabilities
28 known vulnerabilities affecting cisco/security_manager.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7MEDIUM21
Vulnerabilities
Page 2 of 2
CVE-2014-3326MEDIUMCVSS 6.5v4.5v4.62014-07-26
CVE-2014-3326 [MEDIUM] CWE-89 CVE-2014-3326: SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote
SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCup26957.
nvd
CVE-2014-3266MEDIUMCVSS 4.3≤ 4.6v4.0+6 more2014-05-26
CVE-2014-3266 [MEDIUM] CWE-79 CVE-2014-3266: Cross-site scripting (XSS) vulnerability in the web framework in Cisco Security Manager 4.6 and earl
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun65189.
nvd
CVE-2014-3267MEDIUMCVSS 6.8≤ 4.6v4.0+6 more2014-05-26
CVE-2014-3267 [MEDIUM] CWE-352 CVE-2014-3267: Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 a
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make unspecified changes, aka Bug ID CSCuo46427.
nvd
CVE-2014-3265MEDIUMCVSS 4.3v4.22014-05-20
CVE-2014-3265 [MEDIUM] CWE-79 CVE-2014-3265: Cross-site scripting (XSS) vulnerability in the Auto Update Server (AUS) web framework in Cisco Secu
Cross-site scripting (XSS) vulnerability in the Auto Update Server (AUS) web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuo06900.
nvd
CVE-2014-2138MEDIUMCVSS 4.3≤ 4.2v3.0.2+10 more2014-04-02
CVE-2014-2138 [MEDIUM] CWE-20 CVE-2014-2138: CRLF injection vulnerability in the web framework in Cisco Security Manager 4.2 and earlier allows r
CRLF injection vulnerability in the web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCun82349.
nvd
CVE-2010-3036CRITICALCVSS 10.0v3.0.2v3.22010-10-29
CVE-2010-3036 [CRITICAL] CWE-119 CVE-2010-3036: Multiple buffer overflows in the authentication functionality in the web-server module in Cisco Cisc
Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.
nvd
CVE-2009-1161CRITICALCVSS 10.0v3.0v3.1+1 more2009-05-21
CVE-2009-1161 [CRITICAL] CWE-22 CVE-2009-1161: Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0
Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows remote attackers to access arbitrar
nvd
CVE-2008-3820MEDIUMCVSS 6.8v3.1v3.1.1+2 more2009-01-22
CVE-2008-3820 [MEDIUM] CVE-2008-3820: Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes
Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these ports.
nvd
← Previous2 / 2