CVE-2019-15975 details multiple authentication bypass vulnerabilities in Cisco Data Center Network Manager (DCNM). These critical vulnerabilities, rated 9.8 CVSS, allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges. With an EPSS score of 0.85137 and a FAUCET Risk Score of 100/100, the vulnerability is highly exploitable. While not on the KEV catalog, exploit code is publicly available via Metasploit and ExploitDB, and it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.3\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:data_center_network_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.