Vulnslist

find the latest Cisco vulnerabilities

Cisco Digital Network Architecture Center Authentication Bypass Vulnerability

cisco-sa-20180516-dna2 · Critical · Published · Updated

A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and access critical services. The vulnerability is due to a failure to normalize URLs prior to servicing requests. An attacker could exploit this vulnerability by submitting a crafted URL designed to exploit the issue. A successful exploit could allow the attacker to gain unauthenticated access to critical services, resulting in elevated privileges in DNA Center. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180516-dna2

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2018-0271
Cisco Bug IDsCSCvi09394
CVSS ScoreBase 10.0
Base 10.0 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Digital Network Architecture Center (DNA Center)

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2018-0271 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2018-0271 Cisco OpenVuln
Cisco Digital Network Architecture Center (DNA Center) CVE-2018-0271 Cisco OpenVuln