TTCSIRT-261.010620: TT-CSIRT ADVISORY – CISCO SECURITY UPDATES
Cisco has released security updates to address vulnerabilities in multiple Cisco products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.TT-CSIRT encourages users and administrators to review the Cisco Released and apply the necessary updates:
Critical vulnerability:
- CVE-2019-15975-Cisco Data Center Network Manager Authentication Bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-auth-bypass
High-level vulnerabilities:
- CVE-2019-15984-Cisco Data Center Network Manager SQL Injection
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-sql-inject
- CVE-2019-15980-Cisco Data Center Network Manager Path Traversal
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-path-trav - CVE-2019-15978-Cisco Data Center Network Manager Command Injection https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject