Saturday, September 7, 2024
HomeCisco11 Bugs in Cisco Data Center Network Manager Let Hackers Perform RCE,...

11 Bugs in Cisco Data Center Network Manager Let Hackers Perform RCE, SQL Injection, Authentication Bypass Attacks

Published on

Cisco released a security update for several vulnerabilities that affected the Cisco products, including 3 critical remote code execution vulnerabilities that affected the Cisco Datacenter Network Manager let attackers take admin privilege remotely.

Out of 12 vulnerability, 3 marked as “Critical” severity, 7 bugs of categorized as “High” severity, and the rest of the 2 vulnerabilities listed under ” Medium” severity.

Cisco Data Center Network Manager (DCNM) is a network management solution for next-generation Data Centers, and the Cisco DCNM’s goal is to reduce Operation expenses by providing efficient operations and troubleshooting.

- Advertisement - EHA

Critical Severity Vulnerabilities

3 Critical vulnerabilities that exist in the authentication mechanisms of the Cisco Data Center Network Manager (DCNM) could allow unauthenticated and remote attackers to bypass the authentication of executing the arbitrary code in the affected system.

Vulnerabilities affect the earlier version of  Cisco DCNM software 11.3(1) for Microsoft Windows, Linux, and virtual appliance platforms.

All 3 vulnerabilities allow attackers to bypass the authentication of the following:

  • Cisco Data Center Network Manager REST API ( CVE ID: CVE-2019-15975 )
  • Cisco Data Center Network Manager SOAP API {CVE ID: CVE-2019-15976)
  • The web-based management interface of the Cisco DCNM (CVE ID: CVE-2019-15977)

High Severity Vulnerabilities

There are 7 high severity vulnerabilities addressed in this security update and it allows attackers to perform different attackers such as SQL injection, injecting malicious commands and directory traversal attacks.

2 SQL injection vulnerabilities that affected the Cisco Data Center Network Manager Let remote attackers execute arbitrary SQL commands on an affected device. 

Researchers discovered a 3 Cisco Data Center Network Manager Path Traversal Vulnerabilities that allow a remote attacker to conduct directory traversal attacks on an affected device with admin privilege.

2 Command injection vulnerabilities are uncovered in the REST and SOAP API endpoints of Cisco Data Center Network Manager that allows attackers to inject arbitrary commands on the underlying operating system (OS).

Cisco Vulnerabilities Details

Cisco Data Center Network Manager Authentication Bypass VulnerabilitiesCritical
Cisco Data Center Network Manager SQL Injection VulnerabilitiesHigh
Cisco Data Center Network Manager Path Traversal VulnerabilitiesHigh
Cisco Data Center Network Manager Command Injection VulnerabilitiesHigh
Cisco Data Center Network Manager XML External Entity Read Access VulnerabilityMedium
Cisco Data Center Network Manager JBoss EAP Unauthorized Access VulnerabilityMedium

Cisco advised the affected customers to apply these patches immediately to keep the network and application safe and secure from cyber attack.

Cisco has released updates to address this vulnerability; you can find the advisory here.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

BBTok Abuses Legitimate Windows Utility Command Tool to Stay Undetected

Cybercriminals in Latin America have increased their use of phishing scams targeting business transactions...

Predator Spyware Exploiting “one-click” & “zero-click” Flaws

Recent research indicates that the Predator spyware, once thought to be inactive due to...

Tropic Trooper Attacks Government Organizations to Steal Sensitive Data

Tropic Trooper (aka KeyBoy, Pirate Panda, and APT23) is a sophisticated cyberespionage APT group,...

NoiseAttack is a Novel Backdoor That Uses Power Spectral Density For Evasion

NoiseAttack is a new method of secretly attacking deep learning models. It uses triggers...

Free Webinar

Decoding Compliance | What CISOs Need to Know

Non-compliance can result in substantial financial penalties, with average fines reaching up to $4.5 million for GDPR breaches alone.

Join us for an insightful panel discussion with Chandan Pani, CISO - LTIMindtree and Ashish Tandon, Founder & CEO – Indusface, as we explore the multifaceted role of compliance in securing modern enterprises.

Discussion points

The Role of Compliance
The Alphabet Soup of Compliance
Compliance
SaaS and Compliance
Indusface's Approach to Compliance

More like this

SonicWall Access Control Vulnerability Exploited in the Wild

SonicWall has issued an urgent advisory regarding a critical vulnerability in its SonicOS management...

Apache OFBiz for Linux & Windows Vulnerability Allows Unauthenticated Remote Code Execution

A series of vulnerabilities affecting Apache OFBiz has come to light, raising significant cybersecurity...

Veeam Backup & Replication Vulnerabilities Let Attackers Execute Remote Code

Multiple critical vulnerabilities have been identified in Veeam Backup & Replication, a widely-used data...