Cisco
Cisco Industrial Network Director: vulnerabilidades y CVE
Cisco Industrial Network Director tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-20039 | Media (5.5) | 0.20% | — | 15 nov 2024 | A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. |
| CVE-2023-20036 | Crítica (9.9) | 14% | — | 15 nov 2024 | A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. This… |
| CVE-2023-20038 | Alta (8.8) | 0.16% | — | 20 ene 2023 | A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing… |
| CVE-2023-20037 | Media (5.4) | 0.45% | — | 20 ene 2023 | A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks. The vulnerability is due to improper validation of content… |
| CVE-2020-3567 | Media (6.5) | 1.2% | — | 8 oct 2020 | A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU utilization to increase to 100 percent, resulting in a denial of… |
| CVE-2019-15973 | Media (6.1) | 0.80% | — | 26 nov 2019 | A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the… |
| CVE-2019-1976 | Crítica (9.8) | 2.0% | — | 5 sept 2019 | A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The… |
| CVE-2019-1940 | Media (5.9) | 0.98% | — | 17 jul 2019 | A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an… |
| CVE-2019-1882 | Media (5.4) | 0.88% | — | 5 jun 2019 | A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks. The vulnerability is due to improper validation of content… |
| CVE-2019-1881 | Alta (8.8) | 1.3% | — | 5 jun 2019 | A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform… |
| CVE-2019-1861 | Alta (7.2) | 4.3% | — | 5 jun 2019 | A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of files… |
| CVE-2018-15392 | Media (4.3) | 0.45% | — | 5 oct 2018 | A vulnerability in the DHCP service of Cisco Industrial Network Director could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper handling of… |
| CVE-2017-6675 | Media (6.1) | 0.91% | — | 13 jun 2017 | A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system. More… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.