kevmap

Log sources › networkdevice:cli

networkdevice:cli

Inverted view: what can be detected if this is the log you have. Network Devices

20
channels
21
analytics
21
techniques
211
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
CLI command DC0064 Command Execution AN0099 1
CLI command logs DC0064 Command Execution AN0427 1
Commands like 'no logging' or equivalents that disable session history DC0064 Command Execution AN1559 1
Execution of CLI commands altering crypto parameters (e.g., 'crypto key generate rsa modulus 512') DC0064 Command Execution AN0681 1
Execution of commands disabling crypto hardware acceleration (e.g., 'no crypto engine enable') DC0064 Command Execution AN1360 1
Execution of commands like 'show running-config', 'copy running-config', or 'export config' DC0064 Command Execution AN0647 1
Execution of commands such as 'copy tftp flash', 'boot system <image>', 'reload' DC0064 Command Execution AN1570 1
Execution of commands to load, copy, or replace system images (e.g., 'copy tftp flash', 'boot system') DC0064 Command Execution AN0482 1
Execution of privileged commands such as 'copy tftp flash', 'boot system', or 'debug memory' DC0064 Command Execution AN1293 1
Interface commands DC0064 Command Execution AN1233 1
None DC0064 Command Execution AN0563 1
Policy Update DC0064 Command Execution AN0208 1
command logging DC0064 Command Execution AN1073 AN1194 2
command logs DC0064 Command Execution AN0907 1
erase flash:, erase nvram:, format disk DC0064 Command Execution AN0885 1
erase flash:, erase startup-config, format disk DC0064 Command Execution AN0387 1
firewall disable commands or suspicious ACL modifications DC0051 Firewall Rule Modification AN0410 1
format flash:, format disk, reformat commands DC0064 Command Execution AN0830 1
ip ssh pubkey-chain DC0064 Command Execution AN0354 1
shell command DC0064 Command Execution AN1432 1

Techniques detectable from this source

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2010-2883Adobe Acrobat and Reader T1059 Mapped
CVE-2013-0629Adobe ColdFusion T1005 Mapped
CVE-2016-4437Apache Shiro T1059 Mapped
CVE-2017-11292Adobe Flash Player T1005 Mapped
CVE-2017-11882Microsoft Office T1059 Mapped
CVE-2017-5638Apache Struts T1005 T1059 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1059 Mapped
CVE-2017-9805Apache Struts T1059 Mapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1059 Mapped
CVE-2018-0296Cisco Adaptive Security Appliance (ASA) T1005 Mapped
CVE-2018-11776Apache Struts T1059 Mapped
CVE-2018-6789Exim Exim T1059 Mapped
CVE-2018-7600Drupal Drupal Core T1059 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1059 Mapped
CVE-2019-11580Atlassian Crowd and Crowd Data Center T1059 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1005 T1059 Mapped
CVE-2019-13608Citrix StoreFront Server T1005 T1059 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1005 Mapped
CVE-2019-17558Apache Solr T1059 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1059 Mapped
CVE-2019-3396Atlassian Confluence Server and Data Server T1090 Mapped
CVE-2019-3398Atlassian Confluence Server and Data Center T1059 Mapped
CVE-2019-5591Fortinet FortiOS T1005 Mapped
CVE-2020-0787Microsoft Windows T1059 Mapped
CVE-2020-15505Ivanti MobileIron Multiple Products T1059 Mapped
CVE-2020-17530Apache Struts T1059 Mapped
CVE-2020-25506D-Link DNS-320 Device T1059 Mapped
CVE-2020-29557D-Link DIR-825 R1 Devices T1059 Mapped
CVE-2020-29574Sophos CyberoamOS T1059 Mapped
CVE-2020-3452Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1005 Mapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1059 Mapped
CVE-2020-5902F5 BIG-IP T1005 T1059 Stale
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 Mapped
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 Mapped
CVE-2020-8515DrayTek Multiple Vigor Routers T1059 Mapped
CVE-2021-1497Cisco HyperFlex HX T1059 Mapped
CVE-2021-1498Cisco HyperFlex HX T1059 Mapped
CVE-2021-20035SonicWall SMA100 Appliances T1059 Mapped
CVE-2021-21972VMware vCenter Server T1059 Mapped
CVE-2021-22005VMware vCenter Server T1059 Mapped
CVE-2021-22017VMware vCenter Server T1090.001 Mapped
CVE-2021-22204Perl Exiftool T1059 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1059 Mapped
CVE-2021-22893Ivanti Pulse Connect Secure T1059 Mapped
CVE-2021-22894Ivanti Pulse Connect Secure T1059 Mapped
CVE-2021-22900Ivanti Pulse Connect Secure T1059 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1059 T1090 Mapped
CVE-2021-26084Atlassian Confluence Server and Data Center T1059 Mapped
CVE-2021-26085Atlassian Confluence Server T1005 Mapped
CVE-2021-26855Microsoft Exchange Server T1005 T1090 Mapped
CVE-2021-27101Accellion FTA T1005 T1059 Mapped
CVE-2021-27102Accellion FTA T1005 T1059 Mapped
CVE-2021-27103Accellion FTA T1005 Mapped
CVE-2021-27104Accellion FTA T1005 T1059 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1005 Mapped
CVE-2021-31166Microsoft HTTP Protocol Stack T1059 Mapped
CVE-2021-3129Laravel Ignition T1059 Mapped
CVE-2021-34473Microsoft Exchange Server T1048.003 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1059 Mapped
CVE-2021-35464ForgeRock Access Management (AM) T1059 Mapped
CVE-2021-40449Microsoft Windows T1016 Mapped
CVE-2021-41773Apache HTTP Server T1059 Mapped
CVE-2021-42013Apache HTTP Server T1059 Mapped
CVE-2021-42237Sitecore XP T1059 Mapped
CVE-2021-42258BQE BillQuick Web Suite T1059 Mapped
CVE-2021-42321Microsoft Exchange T1059 Mapped
CVE-2021-44168Fortinet FortiOS T1601 Mapped
CVE-2021-45046Apache Log4j2 T1059 Mapped
CVE-2021-45382D-Link Multiple Routers T1059 Mapped
CVE-2022-1040Sophos Firewall T1059 Mapped
CVE-2022-21971Microsoft Windows T1059 Mapped
CVE-2022-21999Microsoft Windows T1059 Mapped
CVE-2022-22047Microsoft Windows T1059 Mapped
CVE-2022-22947VMware Spring Cloud Gateway T1059 Mapped
CVE-2022-22965VMware Spring Framework T1059 Mapped
CVE-2022-23131Zabbix Frontend T1059 Mapped
CVE-2022-23748Audinate Dante Discovery T1059 Mapped
CVE-2022-24521Microsoft Windows T1059 Mapped
CVE-2022-26258D-Link DIR-820L T1059 Mapped
CVE-2022-26500Veeam Backup & Replication T1059 Mapped
CVE-2022-26501Veeam Backup & Replication T1059 Mapped
CVE-2022-29303SolarView Compact T1059 Mapped
CVE-2022-34713Microsoft Windows T1059 Mapped
CVE-2022-35405Zoho ManageEngine T1059 Mapped
CVE-2022-35914Teclib GLPI T1059 Mapped
CVE-2022-36804Atlassian Bitbucket Server and Data Center T1059 Mapped
CVE-2022-37969Microsoft Windows T1059 Mapped
CVE-2022-39197Fortra Cobalt Strike T1059 Mapped
CVE-2022-40684Fortinet Multiple Products T1098.004 Mapped
CVE-2022-41125Microsoft Windows T1059 Mapped
CVE-2022-41328Fortinet FortiOS T1049 Mapped
CVE-2022-42948Fortra Cobalt Strike T1059 Mapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) Server T1059 Mapped
CVE-2022-43939Hitachi Vantara Pentaho Business Analytics (BA) Server T1059 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1059 Mapped
CVE-2023-20118Cisco Small Business RV Series Routers T1059 Mapped
CVE-2023-20273Cisco Cisco IOS XE Web UI T1059 Mapped
CVE-2023-20867VMware Tools T1059 Mapped
CVE-2023-20887VMware Aria Operations for Networks T1059 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1059 Mapped
CVE-2023-22952SugarCRM Multiple Products T1059 Stale
CVE-2023-2533PaperCut NG/MF T1059 Mapped
CVE-2023-26359Adobe ColdFusion T1059 Mapped
CVE-2023-27350PaperCut MF/NG T1059 Mapped
CVE-2023-28252Microsoft Windows T1059 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1059 Mapped
CVE-2023-33246Apache RocketMQ T1059 Mapped
CVE-2023-33538TP-Link Multiple Routers T1059 Mapped
CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) T1059 Mapped
CVE-2023-34362Progress MOVEit Transfer T1005 T1059 Mapped
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM) T1059 Mapped
CVE-2023-36845Juniper Junos OS T1059 Mapped
CVE-2023-36846Juniper Junos OS T1059 Mapped
CVE-2023-36847Juniper Junos OS T1059 Mapped
CVE-2023-36851Juniper Junos OS T1059 Mapped
CVE-2023-36884Microsoft Windows T1005 Stale
CVE-2023-38035Ivanti Sentry T1059 Mapped
CVE-2023-38831RARLAB WinRAR T1005 Mapped
CVE-2023-38950ZKTeco BioTime T1005 Mapped
CVE-2023-40044Progress WS_FTP Server T1059 Mapped
CVE-2023-41179Trend Micro Apex One and Worry-Free Business Security T1059 Mapped
CVE-2023-43770Roundcube Webmail T1059 Mapped
CVE-2023-48365Qlik Sense T1059 Mapped
CVE-2023-48788Fortinet FortiClient EMS T1059 Mapped
CVE-2023-49103ownCloud ownCloud graphapi T1005 Mapped
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway T1005 Mapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcel T1059 Mapped
CVE-2024-0769D-Link DIR-859 Router T1005 Mapped
CVE-2024-11182MDaemon Email Server T1059 Mapped
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) T1059 Mapped
CVE-2024-12987DrayTek Vigor Routers T1059 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1059 Mapped
CVE-2024-20399Cisco NX-OS T1059 Mapped
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM) T1059 Mapped
CVE-2024-21413Microsoft Office Outlook T1059 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1059 Mapped
CVE-2024-23692Rejetto HTTP File Server T1005 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1005 Mapped
CVE-2024-26169Microsoft Windows T1059 Mapped
CVE-2024-27198JetBrains TeamCity T1059 Mapped
CVE-2024-29059Microsoft .NET Framework T1059 Mapped
CVE-2024-34102Adobe Commerce and Magento Open Source T1005 T1059 Mapped
CVE-2024-38475Apache HTTP Server T1005 T1059 Mapped
CVE-2024-41710Mitel SIP Phones T1059 Mapped
CVE-2024-41713Mitel MiCollab T1005 Mapped
CVE-2024-45195Apache OFBiz T1059 Mapped
CVE-2024-4577PHP Group PHP T1059 Mapped
CVE-2024-4671Google Chromium T1059 Mapped
CVE-2024-4761Google Chromium V8 T1059 Mapped
CVE-2024-48248NAKIVO Backup and Replication T1005 Mapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 T1059 Mapped
CVE-2024-4885Progress WhatsUp Gold T1059 Mapped
CVE-2024-4947Google Chromium V8 T1059 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1005 Mapped
CVE-2024-50302Linux Kernel T1005 Mapped
CVE-2024-50603Aviatrix Controllers T1059 Mapped
CVE-2024-5217ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 T1059 Mapped
CVE-2024-53104Linux Kernel T1059 Mapped
CVE-2024-53150Linux Kernel T1005 Mapped
CVE-2024-53197Linux Kernel T1059 Mapped
CVE-2024-55550Mitel MiCollab T1005 Mapped
CVE-2024-56145Craft CMS Craft CMS T1059 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1059 Mapped
CVE-2024-57968Advantive VeraCore T1059 Mapped
CVE-2024-58136Yiiframework Yii T1059 Mapped
CVE-2024-6047GeoVision Multiple Devices T1059 Mapped
CVE-2025-0111Palo Alto Networks PAN-OS T1005 Mapped
CVE-2025-0994Trimble Cityworks T1059 Mapped
CVE-2025-1976Broadcom Brocade Fabric OS T1059 Mapped
CVE-2025-20281Cisco Identity Services Engine T1059 Mapped
CVE-2025-20337Cisco Identity Services Engine T1059 Mapped
CVE-2025-21418Microsoft Windows T1005 Mapped
CVE-2025-21590Juniper Junos OS T1059 Mapped
CVE-2025-22226VMware ESXi, Workstation, and Fusion T1005 Mapped
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1059 Mapped
CVE-2025-23006SonicWall SMA1000 Appliances T1059 Mapped
CVE-2025-24016Wazuh Wazuh Server T1059 Mapped
CVE-2025-24085Apple Multiple Products T1059 Mapped
CVE-2025-24201Apple Multiple Products T1059 Mapped
CVE-2025-24985Microsoft Windows T1059 Mapped
CVE-2025-24991Microsoft Windows T1005 Mapped
CVE-2025-27038Qualcomm Multiple Chipsets T1059 Mapped
CVE-2025-30397Microsoft Windows T1059 Mapped
CVE-2025-30406Gladinet CentreStack T1059 Mapped
CVE-2025-31161CrushFTP CrushFTP T1059 Mapped
CVE-2025-31200Apple Multiple Products T1059 Stale
CVE-2025-31201Apple Multiple Products T1059 Stale
CVE-2025-31324SAP NetWeaver T1059 Mapped
CVE-2025-32433Erlang Erlang/OTP T1059 Mapped
CVE-2025-3248Langflow Langflow T1059 Mapped
CVE-2025-32701Microsoft Windows T1059 Mapped
CVE-2025-32706Microsoft Windows T1059 Mapped
CVE-2025-32709Microsoft Windows T1059 Mapped
CVE-2025-32756Fortinet Multiple Products T1059 Mapped
CVE-2025-33053Microsoft Windows T1059 Mapped
CVE-2025-35939Craft CMS Craft CMS T1059 Mapped
CVE-2025-3928Commvault Web Server T1059 Mapped
CVE-2025-3935ConnectWise ScreenConnect T1059 Mapped
CVE-2025-42599Qualitia Active! Mail T1059 Mapped
CVE-2025-42999SAP NetWeaver T1059 Mapped
CVE-2025-43200Apple Multiple Products T1005 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1059 Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) T1059 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1059 Mapped
CVE-2025-47812Wing FTP Server Wing FTP Server T1059 Mapped
CVE-2025-48927TeleMessage TM SGNL T1005 Mapped
CVE-2025-48928TeleMessage TM SGNL T1005 Mapped
CVE-2025-53770Microsoft SharePoint T1059 Mapped
CVE-2025-6543Citrix NetScaler ADC and Gateway T1059 Mapped
CVE-2025-6554Google Chromium V8 T1059 Mapped