Security Manager
Vendor:
First CVE: Jan 22, 2009 · Active for 17 years
30
Total CVEs
More Total CVEs than 96% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Security Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2009
17 years ago
Most Recent CVE
Jan 14, 2022
1,652 days ago
CVE Severity & Scoring
Security Manager30 CVEs
77%
17%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (63.3%)
Unknown11 (36.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (63.3%)
High0 (0.0%)
Unknown11 (36.7%)
User Interaction
None5 (16.7%)
Unknown11 (36.7%)
Required14 (46.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None19 (63.3%)
Unknown11 (36.7%)
Top CVEs
Signals from CVEs in this product scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27131CRITICAL Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands o | Nov 17, 2020 | 9.8 | 72 | NO | NO |
CVE-2019-12630CRITICAL A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected dev | Oct 2, 2019 | 9.8 | 66 | NO | NO |
CVE-2020-27130CRITICAL A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation o | Nov 17, 2020 | 9.1 | 65 | NO | NO |
CVE-2010-3036HIGH Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary co | Oct 29, 2010 | 10.0 | 32 | NO | NO |
CVE-2019-1903CRITICAL A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerab | Jun 20, 2019 | 9.1 | 31 | NO | NO |
CVE-2009-1161HIGH Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security | May 21, 2009 | 10.0 | 31 | NO | NO |
CVE-2020-27125CRITICAL A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to insuffi | Nov 17, 2020 | 9.8 | 30 | NO | NO |
CVE-2022-20645MEDIUM Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks aga | Jan 14, 2022 | 6.1 | 22 | NO | NO |
CVE-2018-0223MEDIUM A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site | Mar 8, 2018 | 6.1 | 22 | NO | NO |
CVE-2022-20647MEDIUM Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks aga | Jan 14, 2022 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (30 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (30 CVEs).
Media Mentions
Signals from CVEs in this product scope (30 CVEs).
Top CNAs Publishing CVEs For Security Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.9\(0\)qa99 | 1 | 6.1 | 1.8% | 0 | 0 |
| 4.7\(0\) | 1 | 4.3 | 1.6% | 0 | 0 |
| 4.6 | 1 | 6.5 | 2.1% | 0 | 0 |
| 4.5 | 3 | 5.9 | 1.5% | 0 | 0 |
| 4.4 | 2 | 5.5 | 1.2% | 0 | 0 |
| 4.3 | 2 | 5.5 | 1.2% | 0 | 0 |
| 4.2 | 3 | 5.3 | 1.2% | 0 | 0 |
| 4.14 | 1 | 9.1 | 2.2% | 0 | 0 |
| 4.1 | 3 | 5.1 | 1.1% | 0 | 0 |
| 4.0.1 | 3 | 5.1 | 1.1% | 0 | 0 |
| 4.0 | 3 | 5.1 | 1.1% | 0 | 0 |
| 3.3.1 | 1 | 4.3 | 0.9% | 0 | 0 |
| 3.3 | 1 | 4.3 | 0.9% | 0 | 0 |
| 3.2.2 | 1 | 4.3 | 0.9% | 0 | 0 |
| 3.2.1 | 2 | 5.5 | 1.2% | 0 | 0 |
| 3.2 | 4 | 6.6 | 3.5% | 0 | 0 |
| 3.1.1 | 2 | 5.5 | 1.2% | 0 | 0 |
| 3.1 | 3 | 7.0 | 5.0% | 0 | 0 |
| 3.0.2 | 2 | 7.2 | 3.5% | 0 | 0 |
| 3.0 | 1 | 10.0 | 12.6% | 0 | 0 |