Cisco Security Manager vulnerabilities
28 known vulnerabilities affecting cisco/security_manager.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7MEDIUM21
Vulnerabilities
Page 2 of 2
CVE-2022-20637P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20637 [MEDIUM] CWE-79 CVE-2022-20637: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2022-20646P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20646 [MEDIUM] CWE-79 CVE-2022-20646: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2022-20640P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20640 [MEDIUM] CWE-79 CVE-2022-20640: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2022-20643P4MEDIUMCVSS 6.1fixed in 4.242022-01-14
CVE-2022-20643 [MEDIUM] CWE-79 CVE-2022-20643: Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could explo
nvd
CVE-2015-0727P4MEDIUMCVSS 4.3v4.7\(0\)2015-05-15
CVE-2015-0727 [MEDIUM] CWE-79 CVE-2015-0727: Cross-site scripting (XSS) vulnerability in the HTTP module in Cisco Security Manager (CSM) 4.7(0)SP
Cross-site scripting (XSS) vulnerability in the HTTP module in Cisco Security Manager (CSM) 4.7(0)SP1(1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27789.
nvd
CVE-2014-2138P4MEDIUMCVSS 4.3≤ 4.2v3.0.2+10 more2014-04-02
CVE-2014-2138 [MEDIUM] CWE-20 CVE-2014-2138: CRLF injection vulnerability in the web framework in Cisco Security Manager 4.2 and earlier allows r
CRLF injection vulnerability in the web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCun82349.
nvd
CVE-2014-3265P4MEDIUMCVSS 4.3v4.22014-05-20
CVE-2014-3265 [MEDIUM] CWE-79 CVE-2014-3265: Cross-site scripting (XSS) vulnerability in the Auto Update Server (AUS) web framework in Cisco Secu
Cross-site scripting (XSS) vulnerability in the Auto Update Server (AUS) web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuo06900.
nvd
CVE-2014-3266P4MEDIUMCVSS 4.3≤ 4.6v4.0+6 more2014-05-26
CVE-2014-3266 [MEDIUM] CWE-79 CVE-2014-3266: Cross-site scripting (XSS) vulnerability in the web framework in Cisco Security Manager 4.6 and earl
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun65189.
nvd
← Previous2 / 2