VendorsCiscoindustrial_network_directorany version
Vulnerabilities

Cisco Industrial Network Director any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2023-20036
Cisco Industrial Network Director Command Injection Vulnerability
Published 2024-11-15 · Analyzed
9.9EPSS 0.131
CVE-2019-1976
Cisco Industrial Network Director Configuration Data Information Disclosure Vulnerability
Published 2019-09-05 · Modified
9.8EPSS 0.020
CVE-2019-1861
Cisco Industrial Network Director Remote Code Execution Vulnerability
Published 2019-06-05 · Modified
9.0EPSS 0.043
CVE-2023-20038
A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key value stored in the application used to encrypt application data and remote credentials. An attacker could exploit this vulnerability by gaining local access to the server Cisco Industrial Network Director is installed on. A successful exploit could allow the attacker to decrypt data allowing the attacker to access remote systems monitored by Cisco Industrial Network Director.
Published 2023-01-19 · Modified
8.8EPSS 0.002
CVE-2020-3567
Cisco Industrial Network Director Denial of Service Vulnerability
Published 2020-10-08 · Modified
6.8EPSS 0.012
CVE-2019-15973
Cisco Industrial Network Director Reflected Cross-Site Scripting Vulnerability
Published 2019-11-26 · Modified
6.1EPSS 0.008
CVE-2019-1940
Cisco Industrial Network Director Web Services Management Agent Unauthorized Information Disclosure Vulnerability
Published 2019-07-17 · Modified
5.9EPSS 0.010
CVE-2023-20039
Cisco Industrial Network Director File Permissions
Published 2024-11-15 · Analyzed
5.5EPSS 0.002
CVE-2023-20037
A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks. The vulnerability is due to improper validation of content submitted to the affected application. An attacker could exploit this vulnerability by sending requests containing malicious values to the affected system. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published 2023-01-19 · Modified
5.4EPSS 0.004
CVE-2018-15392
Cisco Industrial Network Director DHCP Request Processing Denial of Service Vulnerability
Published 2018-10-05 · Modified
4.3EPSS 0.005