Ncs 5002
Vendor:
First CVE: Jan 26, 2020 · Active for 6 years
22
Total CVEs
More Total CVEs than 94% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 59% of tracked products
9.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Ncs 5002 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2020
6 years ago
Most Recent CVE
Sep 13, 2023
1,047 days ago
CVE Severity & Scoring
Ncs 500222 CVEs
32%
64%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (27.3%)
Network14 (63.6%)
Unknown0 (0.0%)
Physical1 (4.5%)
Adjacent Network1 (4.5%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None21 (95.5%)
Unknown0 (0.0%)
Required1 (4.5%)
Privileges Required
Low6 (27.3%)
High2 (9.1%)
None14 (63.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-20821MEDIUM A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi contai | May 26, 2022 | 6.5 | 67 | YES | NO |
CVE-2020-3569HIGH Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immedi | Sep 23, 2020 | 8.6 | 59 | YES | NO |
CVE-2019-16019HIGH Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote at | Sep 23, 2020 | 8.6 | 28 | NO | NO |
CVE-2021-34720HIGH A vulnerability in the IP Service Level Agreements (IP SLA) responder and Two-Way Active Measurement Protocol (TWAMP) features of Cisco IOS XR Software could allow an unauthenticat | Sep 9, 2021 | 8.6 | 27 | NO | NO |
CVE-2020-3530HIGH A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute that command, even though admin | Sep 4, 2020 | 8.4 | 27 | NO | NO |
CVE-2019-16022HIGH Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote at | Jan 26, 2020 | 8.6 | 27 | NO | NO |
CVE-2019-16020HIGH Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote at | Jan 26, 2020 | 8.6 | 27 | NO | NO |
CVE-2019-15989HIGH A vulnerability in the implementation of the Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial | Jan 26, 2020 | 8.6 | 27 | NO | NO |
CVE-2021-34718HIGH A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device. This vul | Sep 9, 2021 | 8.1 | 26 | NO | NO |
CVE-2020-3284CRITICAL A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to execute unsigned | Nov 6, 2020 | 9.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
2 CVEs
9.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Ncs 5002
Top CWEs
Versions
No cataloged versions.