Permissions, Privileges, and Access Controls in Cisco Data Center Network Manager - CVE-2019-1621

 

Permissions, Privileges, and Access Controls in Cisco Data Center Network Manager - CVE-2019-1621

Published: July 2, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU18963
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1621
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to incorrect permissions settings on the affected software. A remote attacker can use a specific web servlet available on affected devices and request specific URLs to download arbitrary files from the underlying filesystem of the affected device.


Affected software

Cisco Data Center Network Manager

How to mitigate CVE-2019-1621

Install updates from vendor's website.

Cisco Data Center Network Manager - update to 11.2.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins