Security Manager

Vendor:

First CVE: Jan 22, 2009 · Active for 17 years

30
Total CVEs
More Total CVEs than 96% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2009
17 years ago
Most Recent CVE
Jan 14, 2022
1,652 days ago

CVE Severity & Scoring

Security Manager30 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (63.3%)
Unknown11 (36.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (63.3%)
High0 (0.0%)
Unknown11 (36.7%)
User Interaction
None5 (16.7%)
Unknown11 (36.7%)
Required14 (46.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None19 (63.3%)
Unknown11 (36.7%)

Top CVEs

Signals from CVEs in this product scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands o
Nov 17, 20209.872NONO
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected dev
Oct 2, 20199.866NONO
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation o
Nov 17, 20209.165NONO
Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary co
Oct 29, 201010.032NONO
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerab
Jun 20, 20199.131NONO
Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security
May 21, 200910.031NONO
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to insuffi
Nov 17, 20209.830NONO
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks aga
Jan 14, 20226.122NONO
A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site
Mar 8, 20186.122NONO
Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks aga
Jan 14, 20226.121NONO

Exploit Exposure

Signals from CVEs in this product scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (30 CVEs).

Media Mentions

Signals from CVEs in this product scope (30 CVEs).

Top CNAs Publishing CVEs For Security Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.9\(0\)qa9916.11.8%00
4.7\(0\)14.31.6%00
4.616.52.1%00
4.535.91.5%00
4.425.51.2%00
4.325.51.2%00
4.235.31.2%00
4.1419.12.2%00
4.135.11.1%00
4.0.135.11.1%00
4.035.11.1%00
3.3.114.30.9%00
3.314.30.9%00
3.2.214.30.9%00
3.2.125.51.2%00
3.246.63.5%00
3.1.125.51.2%00
3.137.05.0%00
3.0.227.23.5%00
3.0110.012.6%00