CVE-2019-1619
CRITICALCisco Data Center Network Manager - Improper Access Control
Title source: ruleDescription
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper session management on affected DCNM software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to gain administrative access on the affected device.
Exploits (3)
References (6)
Scores
CVSS v3
9.8
EPSS
0.7140
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-284
CWE-798
Status
published
Products (1)
cisco/data_center_network_manager
10.4\(2\)
Published
Jun 27, 2019
Tracked Since
Feb 18, 2026