Home/Product/cisco security manager
Product

cisco security manager

37 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-7720
all versions
HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solu
9.8CRITICAL
CVE-2022-46359
< 3.9
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code exec
8.8HIGH
CVE-2022-46358
< 3.9
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code exec
8.8HIGH
CVE-2022-46357
< 3.9
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code exec
8.8HIGH
CVE-2022-46356
< 3.9
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code exec
8.8HIGH
CVE-2022-20647
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20646
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20645
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20644
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20643
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20642
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20641
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20640
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20639
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20638
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20637
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20636
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2022-20635
< 4.24
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote at
6.1MEDIUM
CVE-2020-27131
<= 4.22
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticate
8.1HIGH
CVE-2020-27130
<= 4.21
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information.
9.1CRITICAL
CVE-2020-27125
<= 4.21
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an af
7.4HIGH
CVE-2019-6142
all versions
It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3. It is strongly recommended that yo
6.1MEDIUM
CVE-2019-12630
< 4.18
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacke
9.8CRITICAL
CVE-2019-1903
all versions
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause
6.5MEDIUM
CVE-2018-0223
all versions
A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager could allow an unauthenticated,
6.1MEDIUM
CVE-2015-0727
all versions
Cross-site scripting (XSS) vulnerability in the HTTP module in Cisco Security Manager (CSM) 4.7(0)SP1(1) allows remote attackers t
CVE-2015-0594
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Cisco Common Services, as used in Cisco Prime LAN Managem
CVE-2014-3326
all versions
SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execut
CVE-2014-0602
<= 6.5.4
Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in NetIQ Security Manager through 6.
CVE-2014-3267
<= 4.6
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote attac
CVE-2014-3266
<= 4.6
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote attackers to
CVE-2014-3265
all versions
Cross-site scripting (XSS) vulnerability in the Auto Update Server (AUS) web framework in Cisco Security Manager 4.2 and earlier a
CVE-2014-2138
<= 4.2
CRLF injection vulnerability in the web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbi
CVE-2013-5488
all versions
Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS), Cisco Security Manager, Cisco Unified Service Monitor
CVE-2010-3036
all versions
Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before
CVE-2009-1161
all versions
Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, a
CVE-2008-3820
all versions
Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL da
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin