Original Release Date: 7/30/2020
Cisco released advisories detailing critical vulnerabilities in two of their products. One is a vulnerability affecting Cisco Data Center Network Manager (DCNM) that could allow any internet user to bypass the web interface login and make actions as administrator of that device. The vulnerability, CVE-2020-3382, is found in the REST API of DCNM and exists due to different applications sharing a static encryption key. A second vulnerability, CVE-2020-3374, affects Cisco SD-WAN vManage software and could allow an internet user to gain privileges beyond what is normally allowed in the user authorization level. This vulnerability can be exploited by sending specially-crafted HTTP requests to the web-based management interface of the affected system. There are no workarounds available for these vulnerabilities.
The NJCCIC recommends administrators apply updates to patch these critical vulnerabilities and additional vulnerabilities after appropriate testing.