The first of these, CVE-2019-1619, is an authentication bypass vulnerability with a CVSS score of 9.8. Describing it in the advisory, Cisco stated,
The vulnerability is due to improper session management on affected DCNM software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to gain administrative access on the affected device.Cisco fixed this vulnerability with the release of DCNM Software v.11.1(1) and later.
Whereas, the other one, CVE-2019-1620, is an arbitrary file upload and remote code execution flaw. This one too has a CVSS base score of 9.8. Regarding this vulnerability, Cisco stated in its advisory,
The vulnerability is due to incorrect permission settings in affected DCNM software. An attacker could exploit this vulnerability by uploading specially crafted data to the affected device. A successful exploit could allow the attacker to write arbitrary files on the filesystem and execute code with root privileges on the affected device.The vendors patched the flaw with Cisco DCNM Software Release 11.2(1) and later.
The users of Cisco DCNM must ensure updating their devices to DCNM Software Release 11.2(1) and later to stay protected from potential risks. Cisco acknowledged the independent researcher Pedro Ribeiro for highlighting all these flaws.
Let us know your thoughts in the comments.