CVE-2019-15975

CRITICAL

Cisco DCNM - Privilege Escalation

Title source: llm

Description

Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Exploits (2)

exploitdb WORKING POC VERIFIED
by mr_me · pythonwebappsjava
https://www.exploit-db.com/exploits/48018
metasploit WORKING POC
by MR_ME · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/networking/cisco_dcnm_auth_bypass.rb

Scores

CVSS v3 9.8
EPSS 0.8514
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-798
Status published

Affected Products (1)

cisco/data_center_network_manager < 11.3\(1\)

Timeline

Published Jan 06, 2020
Tracked Since Feb 18, 2026