VendorsCiscoiot_field_network_directorany version
Vulnerabilities

Cisco Iot Field Network Director any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2020-3531
Cisco IoT Field Network Director Unauthenticated REST API Vulnerability
Published 2020-11-18 · Modified
10.0EPSS 0.022
CVE-2020-26075
Cisco IoT Field Network REST API Insufficient Input Validation Vulnerability
Published 2020-11-18 · Modified
9.0EPSS 0.016
CVE-2020-26072
Cisco IoT Field Network Director SOAP API Authorization Bypass Vulnerability
Published 2020-11-18 · Modified
8.7EPSS 0.010
CVE-2019-1957
Cisco IoT Field Network Director TLS Renegotiation Denial of Service Vulnerability
Published 2019-08-08 · Modified
7.8EPSS 0.020
CVE-2017-6780
A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to cause the system to consume additional memory, eventually forcing the device to restart, aka Memory Exhaustion. The vulnerability is due to insufficient rate-limiting protection. An attacker could exploit this vulnerability by sending a high rate of TCP packets to a specific group of open listening ports on a targeted device. An exploit could allow the attacker to cause the system to consume additional memory. If enough available memory is consumed, the system will restart, creating a temporary denial of service (DoS) condition. The DoS condition will end after the device has finished the restart process. This vulnerability affects the following Cisco products: Connected Grid Network Management System, if running a software release prior to IoT-FND Release 4.0; IoT Field Network Director, if running a software release prior to IoT-FND Release 4.0. Cisco Bug IDs: CSCvc77164.
Published 2017-09-07 · Modified
7.8EPSS 0.017
CVE-2026-20167
Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
Published 2026-05-06 · Analyzed
7.7EPSS 0.003
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2020-3162
Cisco IoT Field Network Director Denial of Service Vulnerability
Published 2020-04-15 · Modified
7.5EPSS 0.017
CVE-2020-3392
Cisco IoT Field Network Director Missing API Authentication Vulnerability
Published 2020-11-18 · Modified
7.5EPSS 0.015
CVE-2020-26076
Cisco IoT Field Network Director Information Disclosure Vulnerability
Published 2020-11-18 · Modified
7.5EPSS 0.013
CVE-2020-26078
Cisco IoT Field Network Director File Overwrite Vulnerability
Published 2020-11-18 · Modified
6.5EPSS 0.015
CVE-2026-20168
Cisco IoT Field Network Director Path Traversal Vulnerability
Published 2026-05-06 · Analyzed
6.5EPSS 0.003
CVE-2026-20169
Cisco IoT Field Network Director Command Injection Vulnerability
Published 2026-05-06 · Analyzed
6.4EPSS 0.002
CVE-2020-26081
Cisco IoT Field Network Director Cross-Site Scripting Vulnerabilities
Published 2020-11-18 · Modified
6.1EPSS 0.008
CVE-2020-26077
Cisco IoT Field Network Director Improper Access Control Vulnerability
Published 2020-11-18 · Modified
5.0EPSS 0.008
CVE-2019-1698
Cisco IoT Field Network Director XML External Entity Vulnerability
Published 2019-02-21 · Modified
4.9EPSS 0.031
CVE-2020-26079
Cisco IoT Field Network Director Unprotected Storage of Credentials Vulnerability
Published 2020-11-18 · Modified
4.9EPSS 0.010
CVE-2020-26080
Cisco IoT Field Network Director Improper Domain Access Control Vulnerability
Published 2020-11-18 · Modified
4.1EPSS 0.007