Lucene search

K
ciscoCiscoCISCO-SA-20200102-DCNM-UNAUTH-ACCESS
HistoryJan 02, 2020 - 4:00 p.m.

Cisco Data Center Network Manager JBoss EAP Unauthorized Access Vulnerability

2020-01-0216:00:00
tools.cisco.com
14

EPSS

0.008

Percentile

81.8%

A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device.

The vulnerability is due to an incorrect configuration of the authentication settings on the JBoss EAP. An attacker could exploit this vulnerability by authenticating with a specific low-privilege account. A successful exploit could allow the attacker to gain unauthorized access to the JBoss EAP, which should be limited to internal system accounts.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-unauth-access [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-unauth-access”]

Affected configurations

Vulners
Node
ciscodata_center_network_managerMatchany
OR
ciscodata_center_network_managerMatchany
VendorProductVersionCPE
ciscodata_center_network_manageranycpe:2.3:a:cisco:data_center_network_manager:any:*:*:*:*:*:*:*

EPSS

0.008

Percentile

81.8%