Vulnslist

find the latest Cisco vulnerabilities

Cisco Digital Network Architecture Center Unauthenticated Access Vulnerability

cisco-sa-20181003-dna-unauth-access · Critical · Published · Updated

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and have direct unauthorized access to critical management functions. The vulnerability is due to an insecure default configuration of the affected system. An attacker could exploit this vulnerability by directly connecting to the exposed services. An exploit could allow the attacker to retrieve and modify critical system files. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-dna-unauth-access

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2018-15386
Cisco Bug IDsCSCvj05082, CSCvj05086
CVSS ScoreBase 9.8
Base 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Digital Network Architecture Center (DNA Center)

Related Products

Product CVE Evidence