Network Services Orchestrator

Vendor:

First CVE: Jun 7, 2018 · Active for 8 years

11
Total CVEs
More Total CVEs than 90% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
18.2%
KEV Rate
Higher KEV Rate than 99% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Network Services Orchestrator over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2018
8 years ago
Most Recent CVE
Apr 16, 2025
467 days ago

CVE Severity & Scoring

Network Services Orchestrator11 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local3 (27.3%)
Network8 (72.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low5 (45.5%)
High1 (9.1%)
None5 (45.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform
Apr 16, 202510.098YESYES
A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to execute arbitrary shell commands with the privileges
Jun 7, 20188.827NONO
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Si
Sep 11, 20248.826NONO
A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is running, which is commonly root
Aug 4, 20217.825NONO
A vulnerability in the Cisco Network Plug and Play server component of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to gain unauthorize
Oct 5, 20187.524NONO
A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access
Nov 18, 20247.523NONO
A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected
Jan 20, 20235.520NONO
A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, loca
May 15, 20247.819NONO
A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a
May 15, 20246.118NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
2 CVEs
18.2% of CVEs· 99th percentile
Metasploit
2 CVEs
18.2% of CVEs· 98th percentile
Nuclei
2 CVEs
18.2% of CVEs· 98th percentile
ExploitDB
1 CVE
9.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Network Services Orchestrator

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.2.218.80.6%00
6.218.80.6%00
6.1.818.80.6%00
6.1.7.118.80.6%00
6.1.718.80.6%00
6.1.6.118.80.6%00
6.1.618.80.6%00
6.1.518.80.6%00
6.1.418.80.6%00
6.1.3.218.80.6%00
6.1.3.118.80.6%00
6.1.318.80.6%00
6.1.2.118.80.6%00
6.1.218.80.6%00
6.1.1218.80.6%00
6.1.11.218.80.6%00
6.1.11.118.80.6%00
6.1.1118.80.6%00
6.1.1018.80.6%00
6.1.118.80.6%00