Nautobot is a network source-of-truth and infrastructure automation platform whose vulnerability profile centers on its device-onboarding plugin, with the durable signal concentrated on credential and secrets-handling weaknesses such as cleartext storage of sensitive information and plaintext password storage. These input-validation and secrets-management issues are characteristic of configuration and automation tooling that interfaces with network devices; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nautobot over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48700MEDIUM The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot down to, in many cases, an IP Address a | Nov 21, 2023 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nautobot.
Media articles that mention a CVE ID that affects a product developed by Nautobot — matched by CVE ID, not by vendor name.