Improper access control in Cisco Data Center Network Manager - CVE-2019-1619
Published: July 2, 2019 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper session management on the affected software. A remote non-authenticated attacker can send a specially crafted HTTP request to a specific web servlet on affected devices, obtain a valid session cookie, bypass authentication and execute arbitrary actions with administrative privileges on the affected device.
Affected software
How to mitigate CVE-2019-1619
Links to Public Exploits and PoC-codes
- Exploit #5998 - Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit) (June 17, 2021)
- Exploit #3509 - Cisco Data Center Network Manager Unauthenticated File Download (July 17, 2020)
- Exploit #93 - Cisco Data Center Network Manager Unauthenticated File Download (March 18, 2020)
- Exploit #1557 - Cisco Data Center Network Manager Unauthenticated Remote Code Execution (March 18, 2020)