Connectrix: Cisco Data Center Network Manager: Arbitrary File Download Vulnerability

Summary: A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) may allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Security Article Type

Security KB

CVE Identifier

CVE-2019-1621 Arbitrary File Download Vulnerability in Data Center Network Manager (DCNM)

Issue Summary

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) may allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device.

The vulnerability is due to incorrect permission settings on affected DCNM software. An attacker pay potentially exploit this vulnerability by connecting to the web-based management interface of an affected device and requesting specific URLs. A successful exploit may allow the attacker to download arbitrary files from the underlying file system of the affected device.

The vulnerability affects Cisco Data Center Network Manager (DCNM) software releases before Release 11.2(1).

Details

An attacker may use a specific web servlet that is available on affected DCNM devices to download arbitrary files from the underlying file system.

In DCNM Software Release 11.0(1) and earlier, an attacker must be authenticated to the DCNM web-based management interface to exploit this vulnerability.

In DCNM Software Release 11.1(1), unauthenticated access to the affected web servlet is available, making it possible for an unauthenticated attacker to exploit this vulnerability.

Recommendations

The vulnerability affects Cisco Data Center Network Manager (DCNM) software releases before Release 11.2(1).

It is suggested to upgrade to 11.2.1 or later to address this issue.

Affected Products

Connectrix MDS-Series Data Center Network Manager
Article Properties
Article Number: 000198353
Article Type: Security KB
Last Modified: 26 May 2026
Version:  2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.