Vulnerability record · CVE-2019-15975 · published 6 January 2020
CVE-2019-15975: Cisco DCNM authentication bypass via hard-coded credentials
Cisco · Data Center Network Manager
Cisco Data Center Network Manager contains multiple authentication mechanism flaws, categorized as hard-coded credentials (CWE-798), that let an unauthenticated remote attacker bypass authentication. Successful abuse grants administrative-level actions on the affected device, making it a severe risk for exposed management planes.
Description
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network-reachable, unauthenticated admin bypass and public exploit references makes this an urgent patch target despite no KEV listing.
What it is
Cisco Data Center Network Manager contains multiple authentication mechanism flaws, categorized as hard-coded credentials (CWE-798), that let an unauthenticated remote attacker bypass authentication. Successful abuse grants administrative-level actions on the affected device, making it a severe risk for exposed management planes.
Impact
An attacker gains administrative privileges on DCNM without valid credentials, allowing arbitrary actions on the managed environment. This can lead to full compromise of the DCNM instance and the data center fabric it controls.
Attack surface
Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), per the CVSS vector. Any internet- or network-exposed DCNM interface is a candidate target.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.96455, 99.879th percentile) and public exploit references exist, including a Packet Storm remote code execution writeup for DCNM 11.2.
What to do
- Apply the Cisco vendor advisory patch for the DCNM authentication bypass (cisco-sa-20200102-dcnm-auth-bypass) as the first action.
- Restrict network access to DCNM management interfaces using firewalls, ACLs or jump hosts; do not expose them to untrusted networks.
- Rotate any credentials or secrets associated with DCNM in case hard-coded values were abused.
- Monitor Cisco advisories for updated fixed versions and confirm the installed DCNM release is supported.
- Where patching is delayed, isolate the DCNM appliance on a segmented management VLAN.
Detection
- Review DCNM authentication and access logs for successful admin sessions without a corresponding valid login or from unexpected source IPs.
- Alert on anomalous administrative actions or configuration changes in DCNM outside normal change windows.
- Hunt for known exploit traffic or payload patterns against DCNM endpoints using network IDS/IPS signatures.
- Audit DCNM for unexpected accounts, sessions or scheduled tasks that could indicate post-exploitation persistence.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/156238/Cisco-Data-Center-Network-Manager-11.2-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-auth-bypass | Vendor Advisory |
| http://packetstormsecurity.com/files/156238/Cisco-Data-Center-Network-Manager-11.2-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-auth-bypass | Vendor Advisory |
Track CVE-2019-15975 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-15975), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.