#VU18963 Permissions, Privileges, and Access Controls in Cisco Data Center Network Manager - CVE-2019-1621

 

#VU18963 Permissions, Privileges, and Access Controls in Cisco Data Center Network Manager - CVE-2019-1621

Published: July 2, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU18963
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:A/U:Green
CVE-ID: CVE-2019-1621
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
Cisco Data Center Network Manager
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to incorrect permissions settings on the affected software. A remote attacker can use a specific web servlet available on affected devices and request specific URLs to download arbitrary files from the underlying filesystem of the affected device.


Remediation

Install updates from vendor's website.

External links