Catalyst Center
Vendor:
First CVE: Mar 11, 2019 · Active for 7 years
25
Total CVEs
More Total CVEs than 95% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Catalyst Center over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 11, 2019
7 years ago
Most Recent CVE
Nov 13, 2025
254 days ago
CVE Severity & Scoring
Catalyst Center25 CVEs
56%
44%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (4.0%)
Network24 (96.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (92.0%)
High2 (8.0%)
Unknown0 (0.0%)
User Interaction
None19 (76.0%)
Unknown0 (0.0%)
Required6 (24.0%)
Privileges Required
Low14 (56.0%)
High4 (16.0%)
None7 (28.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-1264HIGH A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insu | Jan 20, 2021 | 8.8 | 29 | NO | NO |
CVE-2025-20349HIGH A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted container as the root user.
| Nov 13, 2025 | 8.8 | 28 | NO | NO |
CVE-2021-1303HIGH A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execute unauthorized commands on an affected device. The vulnerabi | Jan 20, 2021 | 8.8 | 28 | NO | NO |
CVE-2023-20055HIGH A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface o | Mar 23, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-1257HIGH A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) at | Jan 20, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-15253MEDIUM A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to conduct a stored cross-sit | Feb 5, 2020 | 4.8 | 27 | NO | YES |
CVE-2020-3411HIGH A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive information on an affected system. The vulnerability is due to impro | Aug 17, 2020 | 7.5 | 26 | NO | NO |
CVE-2019-1841HIGH A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authent | Apr 18, 2019 | 8.1 | 26 | NO | NO |
CVE-2024-20350HIGH A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center applia | Sep 25, 2024 | 8.1 | 23 | NO | NO |
CVE-2021-1134HIGH A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote attacker to gain unauthorize | Jun 29, 2021 | 7.4 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Catalyst Center
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.7.4-airgap-mdnac | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.7.4-airgap | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.7.4 | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.7.3-airgap-mdnac | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.7.3-airgap | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.7.3 | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.7.0-va | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.7.0-airgap-mdnac | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.7.0-airgap | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.7.0 | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.6.0-airgap | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.6.0 | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.5.5-airgap-mdnac | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.5.5-airgap | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.5.5-70026 | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.5.5 | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.5.4-airgap-mdnac | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.5.4-airgap | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.5.4 | 1 | 8.1 | 0.4% | 0 | 0 |
| 2.3.5.3-airgap-mdnac | 1 | 8.1 | 0.4% | 0 | 0 |