CVE-2019-1622 is a medium-severity vulnerability affecting Cisco Data Center Network Manager (DCNM) that allows an unauthenticated, remote attacker to retrieve sensitive information. This is due to improper access controls for specific URLs within the web-based management interface. An attacker can exploit this by requesting particular URLs, leading to the download of log files and diagnostic information. While not on the KEV catalog, exploit code, including a Metasploit module for remote code execution, is publicly available, and the vulnerability has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:data_center_network_manager:11.0\(1\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.