« Back to list

Cisco

Cisco Data Center Network Manager: vulnerabilities and CVEs

Cisco Data Center Network Manager has 68 published vulnerabilities, 0 of them in the last 12 months. 7 are rated critical and 2 are listed by CISA as actively exploited.

CVEs68
Last 12 months0
Critical7
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-44487High (7.5)100%⚠ Active exploitationOct 10, 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2021-44228Critical (10)100%⚠ Active exploitationDec 10, 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-3538High (8.1)0.51%—Nov 18, 2024
A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The…
CVE-2023-44487High (7.5)100%⚠ Active exploitationOct 10, 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2021-44228Critical (10)100%⚠ Active exploitationDec 10, 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…
CVE-2021-1250Medium (5.4)0.61%—Jan 20, 2021
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or…
CVE-2021-1249Medium (5.4)0.61%—Jan 20, 2021
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or…
CVE-2021-1248High (7.2)1.9%—Jan 20, 2021
Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more…
CVE-2021-1247High (8.8)1.9%—Jan 20, 2021
Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more…
CVE-2021-1135Medium (4.3)0.63%—Jan 20, 2021
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more…
CVE-2021-1286Medium (6.1)0.94%—Jan 20, 2021
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or…
CVE-2021-1283Medium (5.5)0.28%—Jan 20, 2021
A vulnerability in the logging subsystem of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to view sensitive information in a system log file that should be restricted. The…
CVE-2021-1277Medium (6.5)0.40%—Jan 20, 2021
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API…
CVE-2021-1276Medium (6.5)0.40%—Jan 20, 2021
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API…
CVE-2021-1272High (8.8)1.3%—Jan 20, 2021
A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF)…
CVE-2021-1270Medium (6.5)0.64%—Jan 20, 2021
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For…
CVE-2021-1269Medium (6.3)0.77%—Jan 20, 2021
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For…
CVE-2021-1255Medium (5.4)0.67%—Jan 20, 2021
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more…
CVE-2021-1253Medium (5.4)0.61%—Jan 20, 2021
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or…
CVE-2021-1133High (7.3)1.1%—Jan 20, 2021
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more…
CVE-2020-3523Medium (5.4)0.62%—Aug 26, 2020
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of…
CVE-2020-3522Medium (6.3)0.80%—Aug 26, 2020
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to bypass authorization on an affected device and access sensitive…
CVE-2020-3521Medium (6.5)1.8%—Aug 26, 2020
A vulnerability in a specific REST API of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability…
CVE-2020-3520Medium (5.5)0.29%—Aug 26, 2020
A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, local attacker to obtain confidential information from an affected device. The vulnerability is due to insufficient…
CVE-2020-3519High (8.1)0.97%—Aug 26, 2020
A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The…
CVE-2020-3518Medium (5.4)0.62%—Aug 26, 2020
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of…
CVE-2020-3439Medium (4.8)0.62%—Aug 26, 2020
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of…
CVE-2020-3462Medium (6.3)0.74%—Jul 31, 2020
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability…
CVE-2020-3461Medium (5.3)1.2%—Jul 31, 2020
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. The…
CVE-2020-3460Medium (6.1)0.72%—Jul 31, 2020
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the…
CVE-2020-3386High (8.8)2.0%—Jul 31, 2020
A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device.…
CVE-2020-3384High (8.2)0.79%—Jul 31, 2020
A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system with the…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.007 JavaScript3
  2. T1190 Exploit Public-Facing Application3
  3. T1204.001 Malicious Link2
  4. T1068 Exploitation for Privilege Escalation1
  5. T1105 Ingress Tool Transfer1
  6. T1499.004 Application or System Exploitation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

📰 Related news

Other products by Cisco