Catalyst Center

Vendor:

First CVE: Mar 11, 2019 · Active for 7 years

25
Total CVEs
More Total CVEs than 95% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Catalyst Center over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 11, 2019
7 years ago
Most Recent CVE
Nov 13, 2025
254 days ago

CVE Severity & Scoring

Catalyst Center25 CVEs
All CVEs352,708 CVEs
MediumHigh
Attack Vector
Local1 (4.0%)
Network24 (96.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (92.0%)
High2 (8.0%)
Unknown0 (0.0%)
User Interaction
None19 (76.0%)
Unknown0 (0.0%)
Required6 (24.0%)
Privileges Required
Low14 (56.0%)
High4 (16.0%)
None7 (28.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insu
Jan 20, 20218.829NONO
A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted container as the root user.
Nov 13, 20258.828NONO
A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execute unauthorized commands on an affected device. The vulnerabi
Jan 20, 20218.828NONO
A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface o
Mar 23, 20238.827NONO
A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) at
Jan 20, 20218.827NONO
A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to conduct a stored cross-sit
Feb 5, 20204.827NOYES
A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to impro
Aug 17, 20207.526NONO
A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authent
Apr 18, 20198.126NONO
A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center applia
Sep 25, 20248.123NONO
A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote attacker to gain unauthorize
Jun 29, 20217.423NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Catalyst Center

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.3.7.4-airgap-mdnac18.10.4%00
2.3.7.4-airgap18.10.4%00
2.3.7.418.10.4%00
2.3.7.3-airgap-mdnac18.10.4%00
2.3.7.3-airgap18.10.4%00
2.3.7.318.10.4%00
2.3.7.0-va18.10.4%00
2.3.7.0-airgap-mdnac18.10.4%00
2.3.7.0-airgap18.10.4%00
2.3.7.018.10.4%00
2.3.6.0-airgap18.10.4%00
2.3.6.018.10.4%00
2.3.5.5-airgap-mdnac18.10.4%00
2.3.5.5-airgap18.10.4%00
2.3.5.5-7002618.10.4%00
2.3.5.518.10.4%00
2.3.5.4-airgap-mdnac18.10.4%00
2.3.5.4-airgap18.10.4%00
2.3.5.418.10.4%00
2.3.5.3-airgap-mdnac18.10.4%00