CVE-2019-15977: critical vulnerability in Cisco Data Center Network Manager
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
Published · Updated
Keep watching. It has a public proof of concept.
Cisco Data Center Network Manager has a flaw that lets hackers bypass login requirements and take full control of the system remotely without needing valid credentials. This is critical because attackers can perform any administrative action they want.
Multiple authentication bypass vulnerabilities in Cisco DCNM (CWE-798: hardcoded credentials or weak authentication) allow unauthenticated remote attackers to gain administrative privileges. The attack vector is network-based with no user interaction required; successful exploitation results in complete system compromise with administrative access.
In the same product, most dangerous first.