CVE-2019-15983
Cisco Data Center Network Manager XML External Entity Read Access Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrative privileges on the DCNM application. The vulnerability exists because the SOAP API improperly handles XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by inserting malicious XML content in an API request. A successful exploit could allow the attacker to read arbitrary files from the affected device. Note: The severity of this vulnerability is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.
Una vulnerabilidad en la API SOAP de Cisco Data Center Network Manager (DCNM), podría permitir a un atacante remoto autenticado conseguir acceso de lectura a la información que está almacenada en un sistema afectado. Para explotar esta vulnerabilidad, un atacante requeriría de privilegios administrativos en la aplicación DCNM. La vulnerabilidad existe porque la API SOAP maneja inapropiadamente las entradas de tipo XML External Entity (XXE) cuando se analizan determinados archivos XML. Un atacante podría explotar esta vulnerabilidad insertando contenido XML malicioso en una petición de la API. Una explotación con éxito podría permitir al atacante leer archivos arbitrarios desde el dispositivo afectado. Nota: La gravedad de esta vulnerabilidad está agravada por las vulnerabilidades descritas en el aviso de Vulnerabilidades de Omisión de Autenticación de Cisco Data Center Network Manager, que se publicaron simultáneamente con este.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Data Center Network Manager. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the processing of requests to the getTopologyVlanList SOAP endpoint of DashboardWS. Due to the improper restriction of XML External Entity (XXE) references, a specially crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker could leverage this vulnerability to disclose stored credentials, leading to further compromise.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-09-06 CVE Reserved
- 2020-01-03 CVE Published
- 2024-08-29 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Data Center Network Manager Search vendor "Cisco" for product "Data Center Network Manager" | < 11.3\(1\) Search vendor "Cisco" for product "Data Center Network Manager" and version " < 11.3\(1\)" | - |
Affected
|