CVE-2019-15975
CRITICALCisco DCNM - Privilege Escalation
Title source: llmDescription
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by mr_me · pythonwebappsjava
https://www.exploit-db.com/exploits/48018
metasploit
WORKING POC
by MR_ME · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/networking/cisco_dcnm_auth_bypass.rb
Scores
CVSS v3
9.8
EPSS
0.8514
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-798
Status
published
Affected Products (1)
cisco/data_center_network_manager
< 11.3\(1\)
Timeline
Published
Jan 06, 2020
Tracked Since
Feb 18, 2026