peter bassill · operator
$ cve CVE-2019-1622 JSON

CVE-2019-1622 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 78.9% (pctl 100)

Patch early

A public exploit exists.

Description

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls for certain URLs on affected DCNM software. An attacker could exploit this vulnerability by connecting to the web-based management interface of an affected device and requesting specific URLs. A successful exploit could allow the attacker to download log files and diagnostic information from the affected device.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS78.86% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploityes
Published2019-06-27
Last modified2026-06-17

Affected (1)

VendorProduct
ciscodata center network manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD