Network Services Orchestrator
Vendor:
First CVE: Jun 7, 2018 · Active for 8 years
11
Total CVEs
More Total CVEs than 90% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
18.2%
KEV Rate
Higher KEV Rate than 99% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Network Services Orchestrator over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2018
8 years ago
Most Recent CVE
Apr 16, 2025
467 days ago
CVE Severity & Scoring
Network Services Orchestrator11 CVEs
27%
55%
18%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (27.3%)
Network8 (72.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low5 (45.5%)
High1 (9.1%)
None5 (45.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2025-32433CRITICAL Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform | Apr 16, 2025 | 10.0 | 98 | YES | YES |
CVE-2018-0274HIGH A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to execute arbitrary shell commands with the privileges | Jun 7, 2018 | 8.8 | 27 | NO | NO |
CVE-2024-20381HIGH A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Si | Sep 11, 2024 | 8.8 | 26 | NO | NO |
CVE-2021-1572HIGH A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is running, which is commonly root | Aug 4, 2021 | 7.8 | 25 | NO | NO |
CVE-2018-0463HIGH A vulnerability in the Cisco Network Plug and Play server component of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to gain unauthorize | Oct 5, 2018 | 7.5 | 24 | NO | NO |
CVE-2021-1132HIGH A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access | Nov 18, 2024 | 7.5 | 23 | NO | NO |
CVE-2023-20040MEDIUM A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected | Jan 20, 2023 | 5.5 | 20 | NO | NO |
CVE-2024-20366HIGH A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, loca | May 15, 2024 | 7.8 | 19 | NO | NO |
CVE-2024-20369MEDIUM A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a | May 15, 2024 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
2 CVEs
18.2% of CVEs· 99th percentile
Metasploit
2 CVEs
18.2% of CVEs· 98th percentile
Nuclei
2 CVEs
18.2% of CVEs· 98th percentile
ExploitDB
1 CVE
9.1% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Network Services Orchestrator
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.2.2 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.2 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.8 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.7.1 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.7 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.6.1 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.6 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.5 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.4 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.3.2 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.3.1 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.3 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.2.1 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.2 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.12 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.11.2 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.11.1 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.11 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.10 | 1 | 8.8 | 0.6% | 0 | 0 |
| 6.1.1 | 1 | 8.8 | 0.6% | 0 | 0 |