Known vulnerabilities in Cisco Integrated Management Controller Supervisor
Vendor:
Cisco Systems, Inc
Software CPE:
cpe:2.3:a:cisco_systems:cisco_integrated_management_controller_supervisor:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
8
Public exploits:
3
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU27582 - Improper Access Control CVE-2020-3329 |
CWE-284 | Low | 2.2.1.3 | 07.05.2020 |
SB2020050704 |
||
| #VU20431 - Use of Hard-coded Credentials CVE-2019-1935 |
CWE-798 | High | 2.2.1.0 | 28.08.2019 |
SB2019082810 |
||
| #VU20430 - Improper input validation CVE-2019-1936 |
CWE-20 | Medium | 2.2.1.0 | 28.08.2019 |
SB2019082810 |
||
| #VU20429 - Improper Authentication CVE-2019-1937 |
CWE-287 | High | 2.2.1.0 | 28.08.2019 |
SB2019082810 |
||
| #VU20427 - Improper Authentication CVE-2019-1974 |
CWE-287 | High | 2.2.1.0 | 28.08.2019 |
SB2019082810 |
||
| #VU20379 - Permissions, Privileges, and Access Controls CVE-2019-12634 |
CWE-264 | High | 2.2.1.0 | 23.08.2019 |
SB2019082810 |
||
| #VU15765 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2018-15447 |
CWE-89 | Low | - | 07.11.2018 |
SB2018110721 |
||
| #VU13216 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2018-0149 |
CWE-79 | Low | - | 06.06.2018 |
SB2018060706 SB2018060707 |