Vulnerability record · CVE-2019-1619 · published 27 June 2019
CVE-2019-1619: Cisco DCNM web interface authentication bypass via improper session management
Cisco · Data Center Network Manager
Cisco Data Center Network Manager (DCNM) has an authentication bypass in its web-based management interface caused by improper session management. An unauthenticated remote attacker can send a crafted HTTP request to gain administrative access, making this a critical exposure for any internet- or network-reachable DCNM deployment.
Description
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper session management on affected DCNM software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to gain administrative access on the affected device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, and very high EPSS indicating likely exploitation activity.
What it is
Cisco Data Center Network Manager (DCNM) has an authentication bypass in its web-based management interface caused by improper session management. An unauthenticated remote attacker can send a crafted HTTP request to gain administrative access, making this a critical exposure for any internet- or network-reachable DCNM deployment.
Impact
An attacker gains full administrative control of the affected DCNM device, enabling arbitrary actions with administrative privileges. That access can be used to reconfigure or compromise the managed data center network fabric.
Attack surface
Reachable over the network through the DCNM web management interface via a crafted HTTP request. No authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.828 probability, 99.65th percentile), and multiple third-party references describe unauthenticated remote code execution, indicating public exploit material exists.
What to do
- Apply the Cisco security advisory cisco-sa-20190626-dcnm-bypass patch or fixed DCNM release immediately.
- Restrict access to the DCNM web management interface to trusted management networks only; never expose it to the internet.
- Rotate administrative credentials and review DCNM accounts for unauthorized changes after patching.
- Monitor vendor advisory for updated fixed versions and confirm the installed DCNM build is not vulnerable.
Detection
- Review DCNM web access logs for crafted or anomalous HTTP requests to management endpoints from unauthenticated sources.
- Alert on administrative logins or configuration changes originating from unexpected IP addresses.
- Hunt for new or modified DCNM administrative accounts and unexpected session activity.
- Correlate DCNM management-plane events with network device configuration changes for signs of lateral movement.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-1619 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1619), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.