Known vulnerabilities in Cisco Network Services Orchestrator (NSO)

Software CPE: cpe:2.3:a:cisco_systems:cisco_network_services_orchestrator:*:*:*:*:*:*:*:*
Total vulnerabilities: 9
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco Network Services Orchestrator (NSO) Cisco Network Services Orchestrator (NSO) is affected by 9 known vulnerabilities: 1 critical, 1 high, 3 medium, 4 low Critical High Medium Low

Vulnerabilities (9)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU130437 - Resource exhaustion
CVE-2026-20188
CWE-400 Medium
No
No
6.4.1.3 07.05.2026 SB2026050747
#VU107594 - Missing Authentication for Critical Function
CVE-2025-32433
CWE-306 Critical
Available
Exploited
- 17.04.2025 SB2025041757
SB2025041763
SB2025042002
and 9 more
#VU71102 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-20040
CWE-22 Medium
No
No
5.4.7, 5.5.6, 5.6.7, 5.7.4, 5.8.1 11.01.2023 SB2023011150
#VU59955 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-20655
CWE-78 Low
No
No
4.3.9.1, 4.4.5.6, 4.4.8, 4.5.7, 4.6.1.7, 4.6.2, 4.7.1, 5.1.0.1, 5.2 24.01.2022 SB2022012410
SB2022012512
#VU55606 - Incorrect Privilege Assignment
CVE-2021-1572
CWE-266 Low
No
No
5.4.3.2, 5.5.2.3 05.08.2021 SB2021080516
#VU51221 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-1132
CWE-22 Medium
No
No
5.3.3, 5.4.1 04.03.2021 SB2021030418
#VU29234 - Exposure of sensitive information to an unauthorized actor
CVE-2020-3362
CWE-200 Low
No
No
4.7.7.3, 5.1.4.2 24.06.2020 SB2020062414
#VU14681 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0463
CWE-200 Low
No
No
1.3.0 05.09.2018 SB2018090619
#VU13223 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2018-0274
CWE-78 High
No
No
4.1.6.1, 4.2.4.1, 4.3.3.1, 4.4.2.1 06.06.2018 SB2018060715