Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-1620Path Traversal in Cisco Data Center Network Manager

Severity
9.8CRITICALNVD
EPSS
85.9%
top 0.61%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 27
Latest updateMay 24

Description

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due to incorrect permission settings in affected DCNM software. An attacker could exploit this vulnerability by uploading specially crafted data to the affected device. A successful exploit could allow the attacker to write arbitrary files on the filesystem and execute code with root

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5cisco/cisco_data_center_network_managerunspecified11.2(1)

🔴Vulnerability Details

2
GHSA
GHSA-5r5x-3gwj-56vr: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to u2022-05-24
CVEList
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability2019-06-27

💥Exploits & PoCs

1
Exploit-DB
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)2019-09-03

🔍Detection Rules

2
Suricata
ET EXPLOIT Possible Cisco Data Center Network Manager - Authenticated File Upload (CVE-2019-1620)2021-07-27
Suricata
ET EXPLOIT Possible Cisco Data Center Network Manager - Unauthenticated File Upload (CVE-2019-1620)2021-07-27

📋Vendor Advisories

1
Cisco
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability2019-06-26
CVE-2019-1620 — Path Traversal in Cisco | cvebase