VendorsCiscoiot_field_network_directorall versions
Vulnerabilities

Cisco Iot Field Network Director

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2020-3531
Cisco IoT Field Network Director Unauthenticated REST API Vulnerability
Published 2020-11-18 · Modified
10.0EPSS 0.022
CVE-2020-26075
Cisco IoT Field Network REST API Insufficient Input Validation Vulnerability
Published 2020-11-18 · Modified
9.0EPSS 0.016
CVE-2018-0270
A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and alter the data of existing users and groups on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. If the user has administrative privileges, the attacker could create a new, privileged account to obtain full control over the device interface. This vulnerability affects Connected Grid Network Management System, if running a software release prior to IoT-FND Release 3.0; and IoT Field Network Director, if running a software release prior to IoT-FND Release 4.1.1-6 or 4.2.0-123. Cisco Bug IDs: CSCvi02448.
Published 2018-05-17 · Modified
8.8EPSS 0.007
CVE-2020-26072
Cisco IoT Field Network Director SOAP API Authorization Bypass Vulnerability
Published 2020-11-18 · Modified
8.7EPSS 0.010
CVE-2019-1957
Cisco IoT Field Network Director TLS Renegotiation Denial of Service Vulnerability
Published 2019-08-08 · Modified
7.8EPSS 0.020
CVE-2017-6780
A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to cause the system to consume additional memory, eventually forcing the device to restart, aka Memory Exhaustion. The vulnerability is due to insufficient rate-limiting protection. An attacker could exploit this vulnerability by sending a high rate of TCP packets to a specific group of open listening ports on a targeted device. An exploit could allow the attacker to cause the system to consume additional memory. If enough available memory is consumed, the system will restart, creating a temporary denial of service (DoS) condition. The DoS condition will end after the device has finished the restart process. This vulnerability affects the following Cisco products: Connected Grid Network Management System, if running a software release prior to IoT-FND Release 4.0; IoT Field Network Director, if running a software release prior to IoT-FND Release 4.0. Cisco Bug IDs: CSCvc77164.
Published 2017-09-07 · Modified
7.8EPSS 0.017
CVE-2026-20167
Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
Published 2026-05-06 · Analyzed
7.7EPSS 0.003
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2019-1644
Cisco IoT Field Network Director Resource Exhaustion Denial of Service Vulnerability
Published 2019-01-23 · Modified
7.5EPSS 0.023
CVE-2020-3162
Cisco IoT Field Network Director Denial of Service Vulnerability
Published 2020-04-15 · Modified
7.5EPSS 0.017
CVE-2020-3392
Cisco IoT Field Network Director Missing API Authentication Vulnerability
Published 2020-11-18 · Modified
7.5EPSS 0.015
CVE-2020-26076
Cisco IoT Field Network Director Information Disclosure Vulnerability
Published 2020-11-18 · Modified
7.5EPSS 0.013
CVE-2020-26078
Cisco IoT Field Network Director File Overwrite Vulnerability
Published 2020-11-18 · Modified
6.5EPSS 0.015
CVE-2026-20168
Cisco IoT Field Network Director Path Traversal Vulnerability
Published 2026-05-06 · Analyzed
6.5EPSS 0.003
CVE-2026-20169
Cisco IoT Field Network Director Command Injection Vulnerability
Published 2026-05-06 · Analyzed
6.4EPSS 0.002
CVE-2020-26081
Cisco IoT Field Network Director Cross-Site Scripting Vulnerabilities
Published 2020-11-18 · Modified
6.1EPSS 0.008
CVE-2020-26077
Cisco IoT Field Network Director Improper Access Control Vulnerability
Published 2020-11-18 · Modified
5.0EPSS 0.008
CVE-2019-1698
Cisco IoT Field Network Director XML External Entity Vulnerability
Published 2019-02-21 · Modified
4.9EPSS 0.031
CVE-2020-26079
Cisco IoT Field Network Director Unprotected Storage of Credentials Vulnerability
Published 2020-11-18 · Modified
4.9EPSS 0.010
CVE-2020-26080
Cisco IoT Field Network Director Improper Domain Access Control Vulnerability
Published 2020-11-18 · Modified
4.1EPSS 0.007