September 28, 2026

Flcnyc

Secure Grow Sustain

Just How Insecure is Cisco’s Data Center Network Manager?

FavoriteLoadingInclude to favorites

“A successful exploit could allow for the attacker to perform arbitrary steps by the Relaxation API with administrative privileges”

Just six months in the past Cisco was forced to patch a trio of important vulnerabilities in its Data Center Community Supervisor (DCNM)  — a broadly utilised community management system. The bugs included challenging coded qualifications (lousy) and gave a distant attacker unauthenticated distant code execution as a root consumer (extremely lousy). They have been also “trivial” to exploit.

The bugs have been among the one hundred twenty+ vulnerabilities (truly) in DCNM reported to Cisco by security researcher Steven Seeley. 50 % a year later on, prospects would be forgiven for asking yourself how considerably of a Swiss cheese the item is, simply because the important security holes preserve coming — with some common flavours. (There is some very good information however.)

Data Center Community Supervisor Vulnerabilities: What’s New?

Late Thursday (July 30) Cisco patched nevertheless another important (CVSS nine.8) security vulnerability in DCNM that was the clear consequence of a design flaw.

This bug, CVE-2020-3382, was in the Relaxation API and has an effect on all deployment modes of all Cisco DCNM appliances that have been installed working with .ova or .iso installers, for releases eleven.(1), eleven.1(1), eleven.2(1), and eleven.3(1). (The bug doesn’t impression purchaser-supplied OSs working with the DCNM installer for Home windows or Linux a nutritious chunk of consumers).

Exploitation would allow for — in Cisco’s very own text — an “unauthenticated, distant attacker to bypass authentication and execute arbitrary steps with administrative privileges on an influenced device.” From absolutely nothing, to every little thing, in quick skipping in excess of the DCNM’s panel with out logins to participate in petite God on someone’s community.

Earlier this year SecureData‘s Carl Morris and Wicus Ross advised Laptop Business enterprise Review that Cisco has a “history of issuing security updates that removes static keys or hardcoded credentials”, describing this situation as “in the most flattering phrases equates to extreme laziness and negligence from a computer software advancement and QA level of view”. 

It may establish troubling for prospects, as a consequence, that the vulnerability (once again) exists — as Cisco puts it — “because distinct installations share a static encryption vital.

“An attacker could exploit this vulnerability by working with the static vital to craft a valid session token. A successful exploit could allow for the attacker to perform arbitrary steps by the Relaxation API with administrative privileges.”

(The bug sounds worryingly very similar to January’s flaw enough so to propose that potentially the initial patch was not substantial enough or large-achieving enough. Much better information: this time it was spotted internally, relatively than by a 3rd-occasion).

What else is new?

Cisco also patched 5 large-severity flaws in DCNM, including two command-injection flaws (CVE-2020-3377 and CVE-2020-3384) a route traversal situation (CVE-2020-3383) and another authorisation flaw (CVE-2020-3386) — though an attacker, for the latter, would require some privileges to start off the assault authentication bypass glitch (CVE-2020-3376) letting an unauthenticated, distant attacker to bypass authentication.

Yet another important (CVSS nine.8) vulnerability, CVE-2020-3375, in the meantime, has been patched by Cisco in Cisco SD-WAN Remedy Program. This has an effect on

  • IOS XE SD-WAN Program
  • SD-WAN vBond Orchestrator Program
  • SD-WAN vEdge Cloud Routers
  • SD-WAN vEdge Routers
  • SD-WAN vManage Program
  • SD-WAN vSmart Controller Program

Yet again, it offers a distant, pre-auth attacker root. There are no mitigations, so sysadmins will want to get patching at the earliest chance, if not already completed.

Laptop Business enterprise Review has pressed Cisco on what it is doing to improve good quality assurance internally to sluggish the constant pipeline of pre-auth RCE bugs. We will update this story if/when we have an solution. 

See also: 62,000 Devices Contaminated by Secret Attackers: Menace Vector Nonetheless Not known