#VU18962 Improper access control in Cisco Data Center Network Manager - CVE-2019-1619
Published: July 2, 2019 / Updated: June 17, 2021
Cisco Data Center Network Manager
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper session management on the affected software. A remote non-authenticated attacker can send a specially crafted HTTP request to a specific web servlet on affected devices, obtain a valid session cookie, bypass authentication and execute arbitrary actions with administrative privileges on the affected device.