PT-2020-1432 · Cisco · Cisco Data Center Network Manager

Mr_Me

+1

·

Published

2020-01-02

·

Updated

2020-01-08

·

CVE-2019-15983

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Data Center Network Manager (DCNM) (affected versions not specified)
Description A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information stored on an affected system. The vulnerability exists because the SOAP API improperly handles XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by inserting malicious XML content in an API request, such as the "/api" endpoint, using vulnerable parameters like xmlContent. A successful exploit could allow the attacker to read arbitrary files from the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00410
CVE-2019-15983
ZDI-20-114
ZDI-20-117
ZDI-20-119
ZDI-20-120

Affected Products

Cisco Data Center Network Manager