Tuesday, April 23, 2024

11 Bugs in Cisco Data Center Network Manager Let Hackers Perform RCE, SQL Injection, Authentication Bypass Attacks

Cisco released a security update for several vulnerabilities that affected the Cisco products, including 3 critical remote code execution vulnerabilities that affected the Cisco Datacenter Network Manager let attackers take admin privilege remotely.

Out of 12 vulnerability, 3 marked as “Critical” severity, 7 bugs of categorized as “High” severity, and the rest of the 2 vulnerabilities listed under ” Medium” severity.

Cisco Data Center Network Manager (DCNM) is a network management solution for next-generation Data Centers, and the Cisco DCNM’s goal is to reduce Operation expenses by providing efficient operations and troubleshooting.

Critical Severity Vulnerabilities

3 Critical vulnerabilities that exist in the authentication mechanisms of the Cisco Data Center Network Manager (DCNM) could allow unauthenticated and remote attackers to bypass the authentication of executing the arbitrary code in the affected system.

Vulnerabilities affect the earlier version of  Cisco DCNM software 11.3(1) for Microsoft Windows, Linux, and virtual appliance platforms.

All 3 vulnerabilities allow attackers to bypass the authentication of the following:

  • Cisco Data Center Network Manager REST API ( CVE ID: CVE-2019-15975 )
  • Cisco Data Center Network Manager SOAP API {CVE ID: CVE-2019-15976)
  • The web-based management interface of the Cisco DCNM (CVE ID: CVE-2019-15977)

High Severity Vulnerabilities

There are 7 high severity vulnerabilities addressed in this security update and it allows attackers to perform different attackers such as SQL injection, injecting malicious commands and directory traversal attacks.

2 SQL injection vulnerabilities that affected the Cisco Data Center Network Manager Let remote attackers execute arbitrary SQL commands on an affected device. 

Researchers discovered a 3 Cisco Data Center Network Manager Path Traversal Vulnerabilities that allow a remote attacker to conduct directory traversal attacks on an affected device with admin privilege.

2 Command injection vulnerabilities are uncovered in the REST and SOAP API endpoints of Cisco Data Center Network Manager that allows attackers to inject arbitrary commands on the underlying operating system (OS).

Cisco Vulnerabilities Details

Cisco Data Center Network Manager Authentication Bypass VulnerabilitiesCritical
Cisco Data Center Network Manager SQL Injection VulnerabilitiesHigh
Cisco Data Center Network Manager Path Traversal VulnerabilitiesHigh
Cisco Data Center Network Manager Command Injection VulnerabilitiesHigh
Cisco Data Center Network Manager XML External Entity Read Access VulnerabilityMedium
Cisco Data Center Network Manager JBoss EAP Unauthorized Access VulnerabilityMedium

Cisco advised the affected customers to apply these patches immediately to keep the network and application safe and secure from cyber attack.

Cisco has released updates to address this vulnerability; you can find the advisory here.

Website

Latest articles

Malicious PyPI Package Attacking Discord Users To Steal Credentials

Hackers often target PyPI packages to exploit vulnerabilities and inject malicious code into widely...

Beware Of Weaponized Zip Files That Deliver WINELOADER Malware

APT29, a Russian threat group, targeted German political parties with a new backdoor called...

Citrix UberAgent Flaw Let Attackers Elevate Privileges

A significant vulnerability has been identified in Citrix's monitoring tool, uberAgent.If exploited, this flaw...

Hackers Group Claims To Have Broke Into IDF & Stolen Documents

Anonymous claims a successful cyberattack against the Israeli Defence Force (IDF), gaining access to...

VMware ESXi Shell Service Exploit on Hacking Forums: Patch Now

A new exploit targeting VMware ESXi Shell Service has been discovered and is circulating...

Windows MagicDot Path Flaw Lets Attackers Gain Rootkit-Like Abilities

A new vulnerability has been unearthed, allowing attackers to gain rootkit-like abilities on Windows...

Alert! Zero-day Exploit For WhatsApp Advertised On Hacker Forums

A zero-day exploit targeting the popular messaging app WhatsApp has been advertised on underground...
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

WAAP/WAF ROI Analysis

Mastering WAAP/WAF ROI Analysis

As the importance of compliance and safeguarding critical websites and APIs grows, Web Application and API Protection (WAAP) solutions play an integral role.
Key takeaways include:

  • Pricing models
  • Cost Estimation
  • ROI Calculation

Related Articles