ID:5998 - Exploit for Improper access control in Cisco Data Center Network Manager - CVE-2019-1619

 
Main Vulnerability Database Exploits ID:5998 - Exploit for Improper access control in Cisco Data Center Network Manager - CVE-2019-1619

ID:5998 - Exploit for Improper access control in Cisco Data Center Network Manager - CVE-2019-1619

Published: June 17, 2021


Vulnerability identifier: #VU18962
Vulnerability risk: High
CVE-ID: CVE-2019-1619
CWE-ID: CWE-284
Exploitation vector: Remote access
Vulnerable software:
Cisco Data Center Network Manager

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.

The vulnerability exists due to improper session management on the affected software. A remote non-authenticated attacker can send a specially crafted HTTP request to a specific web servlet on affected devices, obtain a valid session cookie, bypass authentication and execute arbitrary actions with administrative privileges on the affected device.


Remediation

Install updates from vendor's website.