Security News > 2020 > January > Critical Cisco Flaws Now Have PoC Exploit

Proof-of-concept exploit code has been published for critical flaws impacting the Cisco Data Center Network Manager tool for managing network platforms and switches.
The three critical vulnerabilities in question impact DCNM, a platform for managing Cisco data centers that run Cisco's NX-OS - the network operating system used by Cisco's Nexus-series Ethernet switches and MDS-series Fibre Channel storage area network switches.
Two of the flaws are authentication bypass vulnerabilities in the REST API and SOAP API endpoints for Cisco DCNM. Representational State Transfer is an architecture style for designing networked applications, according to RestFulApi.net; while Simple Object Access Protocol is a standard communication protocol system that allows processes using different operating systems to communicate via HTTP and its XML, according to a DZone description.
With the PoC exploit code now available, Cisco is urging customers to update.
"The Cisco Product Security Incident Response Team is aware that proof-of-concept exploit code is available for the vulnerabilities that are described in this advisory," according to Cisco's advisory, which was updated on Wednesday.
News URL
https://threatpost.com/cisco-dcnm-flaw-exploit/151949/
Related news
- Cisco warns of denial of service flaw with PoC exploit code (source)
- Cisco fixes ClamAV vulnerability with available PoC and critical Meeting Management flaw (source)
- Hackers exploit critical Aviatrix Controller RCE flaw in attacks (source)
- Cisco Fixes Critical Privilege Escalation Flaw in Meeting Management (CVSS 9.9) (source)
- Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management (source)
- Hackers exploit critical unpatched flaw in Zyxel CPE devices (source)
- Cisco Patches Critical ISE Vulnerabilities Enabling Root CmdExec and PrivEsc (source)
- Critical Cisco ISE bug can let attackers run commands as root (source)
- SonicWall firewall bug leveraged in attacks after PoC exploit release (source)
- PoC exploit for Ivanti Endpoint Manager vulnerabilities released (CVE-2024-13159) (source)