vendor:
Data Center Network Manager
by:
mr_me
7.2
CVSS
HIGH
SQL Injection Remote Code Execution
89
CWE
Product Name: Data Center Network Manager
Affected Version From: 11.2(1)
Affected Version To: 11.2(1)
Patch Exists: YES
Related CWE: CVE-2019-15976, CVE-2019-15984
CPE: a:cisco:dcnm:11.2.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
Cisco Data Center Network Manager HostEnclHandler getVmHostData SQL Injection Remote Code Execution Vulnerability
A vulnerability in the HostEnclHandler getVmHostData function of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system with the privileges of the web server. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected system. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system with the privileges of the web server.
Mitigation:
Upgrade to Cisco Data Center Network Manager (DCNM) version 11.2(1) or later.