SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Cisco releases critical security updates for Data Center Network Manager (DCNM)

Cisco releases critical security updates for Data Center Network Manager (DCNM)

Jan 6, 2020By Vidita V Koushik3 min read

Cisco released security updates for Cisco Data Center Network Manager (DCNM), a platform for managing Cisco’s data center deployments, switches and fabric extenders that run NX-OS. A total of 12 vulnerabilities in DCNM were addressed in 6 advisories, one of which has been rated critical, three rated high and two rated medium in severity.

Summary of security updates for Cisco Data Center Network Manager (DCNM):

  • CVE-2019-15975, CVE-2019-15976, CVE-2019-15977: Multiple vulnerabilities in Cisco DCNM could allow an unauthenticated remote attacker with administrative privileges to bypass authentication mechanisms and execute arbitrary actions on an affected device. The flaws exist in REST API(CVE-2019-15975) and SOAP API(CVE-2019-15976) endpoints due to a static encryption key is shared between installations. An attacker who uses the static key to craft a valid session token could perform arbitrary actions through REST and SOAP API with admin privileges in web-based management interface due to the presence of static credentials.
    CVE-2019-15977 is a flaw in the web-based management interface of Cisco DCNM due to the presence of static credentials. An attacker who exploits the bug using static credentials to authenticate against the user interface, could gain access to certain sections of the web interface and obtain confidential information.

  • CVE-2019-15984, CVE-2019-15985: Multiple vulnerabilities exist in the REST and SOAP API endpoints of Cisco DCNM allow an authenticated remote attacker to execute arbitrary SQL commands. These flaws exist due to insufficient validation of user-supplied input to the API. An unauthorized attacker who sends a crafted request to the API can view sensitive information, make changes to the system, or execute commands within the underlying operating system which affects the availability of the device.

  • CVE-2019-15980, CVE-2019-15981, CVE-2019-15982: Multiple vulnerabilities exist in the REST and SOAP API endpoints of Cisco DCNM allow an authenticated remote attacker to conduct directory traversal attacks on an affected device. These flaws exist due to insufficient validation of user-supplied input to the API. An attacker who sends crafted request to the API could read, write, or execute arbitrary files in the system with full administrative privileges.
  • CVE-2019-15978, CVE-2019-15979: Multiple vulnerabilities exist in the REST and SOAP API endpoints of Cisco DCNM allow an authenticated remote attacker with admin privileges to inject arbitrary commands on the underlying OS. These flaws exist due to insufficient validation of user-supplied input to the API. An attacker who sends crafted request to the API could execute arbitrary files in the system with full administrative privileges.

  • CVE-2019-15983 : A vulnerability in the SOAP API of Cisco DCNM allows an authenticated, remote attacker to gain read access to information stored on an affected system. The flaw exists due to improper handling of XML External Entity (XXE) entries in SOAP API when parsing certain XML files. An attacker who inserts malicious XML content in an API request could read arbitrary files from the device.

  • CVE-2019-15999 : A vulnerability in the application environment of Cisco DCNM could allow an authenticated remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP). The flaw exists due to incorrect configuration of the authentication settings on JBoss EAP.

Affected Products

Cisco DCNM software before Release 11.3(1)

Impact

These vulnerabilities allow an attacker to bypass authentication mechanisms, inject SQL commands, traverse directories, gain unauthorized access and read sensitive data from the affected system.

Solution

Cisco has fixed these vulnerabilities in Cisco DCNM Software release 11.3(1). We strongly recommend upgrading Cisco DCNM to the latest version provided by the vendor.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026