Forgotten Debugging Tool and Password Leaves Cisco DCNM Vulnerable
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Cisco Prime Data Center Network Manager (DCNM)
Cisco Prime DCNM releases 10.1(1), 10.1(2) and 10.2(1) for Windows, LinuxThreat details
The impact is considered high with the level of access and trust the DCNM has within a network lateral movement and traffic manipulation allowing further attacks and compromise across the network is a real possibility.
Cisco Data Center Network Manager offers network management system (NMS) support for LANs and SANs. The products cover Cisco Nexus 5000, 6000, 7000, and 9000 Series Switches in Cisco NX-OS mode and MDS 9000 series SAN switches.
The first vulnerability is located within the role-based access control (RBAC) functionality of the product that during development had a debugging tool switched on. The issue is that the tool remained switched on after development had completed and went unnoticed by Cisco QA teams and was pushed to customers. This tool enables remote administrator access to the device over a TCP connection, requires no form of authentication and provides a user with full root privileges which could be used to gain access to sensitive information as well as execute code on the device as a super user.
The second identified vulnerability refers to a default user account that was left within the product and contains a static password which is created at the time of installation. With access to the account details, a remote attacker could connect to the administrator console providing full access to the managed network.
Both of the above-mentioned vulnerabilities were patched in the company’s latest release 10.2(1). Cisco confirmed that there are no other identified workarounds.
Remediation steps
Last edited: 17 February 2020 11:31 am