Cisco

Network Services Orchestrator

14 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warning Media report Exploit
  • EPSS 66.37%
  • Published 16.04.2025 21:34:37
  • Last modified 30.07.2025 19:24:19

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in S...

  • EPSS 0.3%
  • Published 18.11.2024 16:15:08
  • Last modified 05.08.2025 13:21:24

A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access sensitive data. This vulnerability exists because the web-management...

  • EPSS 0.54%
  • Published 15.11.2024 16:15:20
  • Last modified 18.11.2024 17:11:56

A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient validation of a process argument on an a...

  • EPSS 0.32%
  • Published 11.09.2024 17:15:12
  • Last modified 08.10.2024 21:43:28

A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an...

  • EPSS 0.43%
  • Published 16.05.2024 14:15:08
  • Last modified 25.07.2025 14:39:47

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerabilit...

  • EPSS 0.14%
  • Published 16.05.2024 14:15:08
  • Last modified 30.07.2025 19:17:36

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerabilit...

  • EPSS 0.15%
  • Published 15.05.2024 18:15:09
  • Last modified 25.03.2025 17:49:13

A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, local attacker to elevate privileges to root on an affected device. Thi...

  • EPSS 0.22%
  • Published 15.05.2024 18:15:09
  • Last modified 25.03.2025 17:44:05

A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input ...

  • EPSS 1.41%
  • Published 20.01.2023 07:15:15
  • Last modified 21.11.2024 07:40:24

A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vulnerability...

Warning Exploit
  • EPSS 94.36%
  • Published 10.12.2021 10:15:09
  • Last modified 08.08.2025 18:52:00

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An atta...