CVE-2019-15977
HIGHCisco Data Center Network Manager < 11.3(1) - Unauthenticated Authentication Bypass via Hard-coded Credentials
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-15977.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in Cisco Data Center Network Manager (DCNM) by leaking credentials, bypassing authentication, and executing arbitrary commands to achieve remote code execution. The exploit chains multiple steps, including credential leakage, session establishment, and command injection via the LanFabricImpl createLanFabric endpoint.
Description
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Exploits (1)
This exploit demonstrates a command injection vulnerability in Cisco Data Center Network Manager (DCNM) by leaking credentials, bypassing authentication, and executing arbitrary commands to achieve remote code execution. The exploit chains multiple steps, including credential leakage, session establishment, and command injection via the LanFabricImpl createLanFabric endpoint.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N