VDB
CVE-2019-1620
CVE-2019-1620
PUBLISHED
CVSS 9.800000190734863 CRITICAL
De multiples vulnérabilités ont été découvertes dans Cisco Data Center Network Manager. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un contournement de la politique de sécurité et une atteinte à l'intégrité des données.
EPSS 85.62% · 99.4th percentile
Risk Scores
CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
85.62%
99.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | data_center_network_manager | 11.0\(1\) |
| Cisco | Cisco Data Center Network Manager | unspecified |
| Cisco | N/A |
Exploit Intelligence
- CIRCL exploited: CVE-2019-1620 (circl-sighting)
- CIRCL seen: CVE-2019-1620 (circl-sighting)
- CIRCL seen: CVE-2019-1620 (circl-sighting)
- CIRCL seen: CVE-2019-1620 (circl-sighting)
- 20190709 Cisco Data Center Manager multiple vulns; RCE as root (circl)
- http://packetstormsecurity.com/files/154304/Cisco-Data-Center-Network-Manager-Unauthenticated-Remote-Code-Execution.html (circl)
- 20190626 Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability (circl)
- http://packetstormsecurity.com/files/153546/Cisco-Data-Center-Network-Manager-11.1-1-Remote-Code-Execution.html (circl)
- 20190708 Cisco Data Center Manager multiple vulns; RCE as root (circl)
- 108906 (circl)
…and 8 more exploits
Timeline
- Jun 26, 2019 CVE Published
- Jul 8, 2019 PoC Published
- Sep 2, 2019 PoC Published
- Sep 2, 2019 PoC Published
- Sep 3, 2019 PoC Published
- Apr 14, 2021 EPSS Score
- Jul 27, 2021 PoC Published
- Aug 24, 2021 EPSS Score
- Sep 16, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
References
- 20190626 Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability vendor-advisory
- 108906 vdb
- 20190708 Cisco Data Center Manager multiple vulns; RCE as root mailing-list
- http://packetstormsecurity.com/files/153546/Cisco-Data-Center-Network-Manager-11.1-1-Remote-Code-Execution.html url
- 20190709 Cisco Data Center Manager multiple vulns; RCE as root mailing-list
- http://packetstormsecurity.com/files/154304/Cisco-Data-Center-Network-Manager-Unauthenticated-Remote-Code-Execution.html url
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-bypass advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190626-dcnm-file-dwnld advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-1620 advisory