Known vulnerabilities in Crosswork Network Services Orchestrator

Software CPE: cpe:2.3:a:cisco_systems:crosswork_network_services_orchestrator:*:*:*:*:*:*:*:*
Total vulnerabilities: 5
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Crosswork Network Services Orchestrator Crosswork Network Services Orchestrator is affected by 5 known vulnerabilities: 2 medium, 3 low Critical High Medium Low

Vulnerabilities (5)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU97228 - Improper Authentication
CVE-2024-20381
CWE-287 Medium
No
No
5.5.10.1, 5.6.14.3, 5.7.16, 5.8.13.1, 6.0.13, 6.1.8.1, 6.1.9, 6.2.3 13.09.2024 SB2024091311
#VU89580 - External Control of File Name or Path
CVE-2024-20366
CWE-73 Low
No
No
5.0.5, 6.0.2 16.05.2024 SB2024051609
#VU89579 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-20369
CWE-601 Medium
No
No
5.5.10.1, 5.6.14.3, 5.7.15, 5.8.13.1, 6.0.12, 6.1.7, 6.2.2 16.05.2024 SB2024051610
#VU89578 - Incorrect Privilege Assignment
CVE-2024-20389
CWE-266 Low
No
No
6.0.12, 6.2.2 16.05.2024 SB2024051610
SB2024051620
#VU89570 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-20326
CWE-78 Low
No
No
5.5.10.1, 5.6.14.3, 5.7.15, 5.8.13.1, 6.0.12, 6.1.7, 6.2.2 16.05.2024 SB2024051610
SB2024051620