Security News > 2020 > January > Critical Cisco Flaws Now Have PoC Exploit

Proof-of-concept exploit code has been published for critical flaws impacting the Cisco Data Center Network Manager tool for managing network platforms and switches.
The three critical vulnerabilities in question impact DCNM, a platform for managing Cisco data centers that run Cisco's NX-OS - the network operating system used by Cisco's Nexus-series Ethernet switches and MDS-series Fibre Channel storage area network switches.
Two of the flaws are authentication bypass vulnerabilities in the REST API and SOAP API endpoints for Cisco DCNM. Representational State Transfer is an architecture style for designing networked applications, according to RestFulApi.net; while Simple Object Access Protocol is a standard communication protocol system that allows processes using different operating systems to communicate via HTTP and its XML, according to a DZone description.
With the PoC exploit code now available, Cisco is urging customers to update.
"The Cisco Product Security Incident Response Team is aware that proof-of-concept exploit code is available for the vulnerabilities that are described in this advisory," according to Cisco's advisory, which was updated on Wednesday.
News URL
https://threatpost.com/cisco-dcnm-flaw-exploit/151949/
Related news
- PoC exploit for critical Erlang/OTP SSH bug is public (CVE-2025-32433) (source)
- Critical Erlang/OTP SSH pre-auth RCE is 'Surprisingly Easy' to exploit, patch now (source)
- Critical Erlang/OTP SSH RCE bug now has public exploits, patch now (source)
- Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028) (source)
- Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromised (source)
- ⚡ Weekly Recap: Critical SAP Exploit, AI-Powered Phishing, Major Breaches, New CVEs & More (source)
- Apache Parquet exploit tool detect servers vulnerable to critical flaw (source)
- PoC exploit for SysAid pre-auth RCE released, upgrade quickly! (source)
- Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT (source)
- China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide (source)