UCF STIG Viewer Logo

Cisco Prime Data Center Network Manager (DCNM) Remote Command Execution Vulnerability


Overview

Finding ID Version Rule ID IA Controls Severity
V-34934 2012-B-0108 SV-46066r2_rule ECMT-1 ECMT-2 VIVM-1 High
Description
Cisco has released a security advisory addressing a vulnerability in Prime Data Center Network Manager (DCNM). Cisco Prime Data Center Network Manager, previously known as Cisco Data Center Network Manager, is a network management application that combines the management of Ethernet and storage networks into a single dashboard to help network and storage administrators manage and troubleshoot health and performance across different families of Cisco products that run Cisco NX-OS Software. To exploit this vulnerability, an attacker would send arbitrary commands via RMI services to a target system. If successfully exploited, the attacker would gain the ability to execute arbitrary commands on the affected system.<br><br> At this time, there is a known exploit associated with the JBoss configuration which causes this vulnerability; USCYBERCOM is not aware of any DoD related incidents.<br><br>
STIG Date
VMware ESXi Server 5.0 Security Technical Implementation Guide 2013-09-12

Details

Check Text ( None )
None
Fix Text (None)
None