Vulnerabilities > Cisco > Prime Data Center Network Manager

DATE CVE VULNERABILITY TITLE RISK
2018-10-05 CVE-2018-0464 Path Traversal vulnerability in Cisco Prime Data Center Network Manager
A vulnerability in Cisco Data Center Network Manager software could allow an authenticated, remote attacker to conduct directory traversal attacks and gain access to sensitive files on the targeted system.
network
low complexity
cisco CWE-22
8.1
2018-05-02 CVE-2018-0258 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco products
A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files.
network
low complexity
cisco CWE-434
critical
9.8
2018-03-08 CVE-2018-0144 Cross-site Scripting vulnerability in Cisco Prime Data Center Network Manager 10.4(1.109)
A vulnerability in the web-based management interface of Cisco Prime Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
6.1
2017-06-08 CVE-2017-6640 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Prime Data Center Network Manager 10.1.0/10.1(1)/10.1(2)
A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password.
network
low complexity
cisco CWE-770
critical
9.8
2017-06-08 CVE-2017-6639 Missing Authorization vulnerability in Cisco Prime Data Center Network Manager 10.1.0/10.1(1)/10.1(2)
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affected system.
network
low complexity
cisco CWE-862
critical
9.8