Skip to main content

Forgotten Debugging Tool and Password Leaves Cisco DCNM Vulnerable

In a recent Cisco advisory release, two vulnerabilities have been found within Cisco Prime Data Centre Network Manager (DCNM). If successfully exploited, it could allow a remote, unauthenticated actor access to the administrative console as well as the ability to execute arbitrary code on the target machine.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

In a recent Cisco advisory release, two vulnerabilities have been found within Cisco Prime Data Centre Network Manager (DCNM). If successfully exploited, it could allow a remote, unauthenticated actor access to the administrative console as well as the ability to execute arbitrary code on the target machine.

Affected platforms

The following platforms are known to be affected:

Cisco Prime Data Center Network Manager (DCNM)

Cisco Prime DCNM releases 10.1(1), 10.1(2) and 10.2(1) for Windows, Linux

Threat details

The impact is considered high with the level of access and trust the DCNM has within a network lateral movement and traffic manipulation allowing further attacks and compromise across the network is a real possibility.

Cisco Data Center Network Manager offers network management system (NMS) support for LANs and SANs. The products cover Cisco Nexus 5000, 6000, 7000, and 9000 Series Switches in Cisco NX-OS mode and MDS 9000 series SAN switches.

The first vulnerability is located within the role-based access control (RBAC) functionality of the product that during development had a debugging tool switched on. The issue is that the tool remained switched on after development had completed and went unnoticed by Cisco QA teams and was pushed to customers. This tool enables remote administrator access to the device over a TCP connection, requires no form of authentication and provides a user with full root privileges which could be used to gain access to sensitive information as well as execute code on the device as a super user.

The second identified vulnerability refers to a default user account that was left within the product and contains a static password which is created at the time of installation. With access to the account details, a remote attacker could connect to the administrator console providing full access to the managed network.

Both of the above-mentioned vulnerabilities were patched in the company’s latest release 10.2(1). Cisco confirmed that there are no other identified workarounds.


Remediation steps

Type Step
  • Ensure deployments of DCNM are fully patched with the latest available version (10.2(1). or later).
  • Ensure access to management console is only available to trusted network and blocked from others such as the internet where ever possible.
  • Ensure the DCNM is protected with a firewall filtering all connections to unused TCP ports.

Last edited: 17 February 2020 11:31 am