Rewterz
Rewterz Threat Advisory – Cisco NX-OS and Switches – Critical Vulnerabilities
January 6, 2020
Rewterz
Rewterz Threat Alert – IcedID banking Trojan – IOCs
January 6, 2020

Rewterz Threat Advisory – Cisco Data Center Network Manager Multiple Vulnerabilities

Severity

High

Analysis Summary

In addition to the critical vulnerabilities reported in previous advisory, Cisco Data Center Network Manager is also vulnerable to multiple High severity and Medium severity vulnerabilities. 


SQL Injection: HIGH SEVERITY

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. 
CVE-2019-15984 & CVE-2019-15985

Path Traversal: HIGH SEVERITY

Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device.
CVE-2019-15980, CVE-2019-15981 & CVE-2019-15982

Command Injection: HIGH SEVERITY

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). 
CVE-2019-15978 & CVE-2019-15979

XML External Entity Read Access: MEDIUM SEVERITY

A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrative privileges on the DCNM application.
CVE-2019-15983 
 

JBoss EAP Unauthorized Access: MEDIUM SEVERITY

A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. 
CVE-2019-15999

Impact

  • Execution of arbitrary SQL commands
  • Directory Traversal Attacks
  • Remote code execution
  • Information disclosure
  • Unauthorized access

Affected Vendors

Cisco

Affected Products

Cisco DCNM software releases earlier than Release 11.3(1) for Microsoft Windows Linux and virtual appliance platforms

Remediation

Update to Cisco DCNM Software releases 11.3(1) and later.
No other workarounds are available.