Record summary

CVE-2019-15999 has a selected CVSS score of 6.3 (medium); EIP currently links 1 catalogued exploit.

Description

A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. The vulnerability is due to an incorrect configuration of the authentication settings on the JBoss EAP. An attacker could exploit this vulnerability by authenticating with a specific low-privilege account. A successful exploit could allow the attacker to gain unauthorized access to the JBoss EAP, which should be limited to internal system accounts.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 15, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Cisco Data Center Network Manager

Browse Cisco / Cisco Data Center Network Manager
CVE ListVersion range not suppliedaffected

Proofs of concept

1

Catalogued exploits

ExploitDBCisco DCNM JBoss 10.4 - Credential LeakageExploitDB exploitby hantwisterNot analyzed1 file
ExploitDB

PoC details

References

3