← back
CVE-2019-1621highCWE-264

Cisco Data Center Network Manager Arbitrary File Download Vulnerability

41Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.5epss 30%
from disclosure to weapon0 days
Published on NVDJun 27
metasploitJun 26
exploitation probability
30%top 2% of all CVEs
observed exploitation
nono source reports it
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device. The vulnerability is due to incorrect permissions settings on affected DCNM software. An attacker could exploit this vulnerability by connecting to the web-based management interface of an affected device and requesting specific URLs. A successful exploit could allow the attacker to download arbitrary files from the underlying filesystem of the affected device.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N