Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-0268

Опубликовано: 17 мая 2018
Источник: nvd
CVSS3: 10
CVSS2: 10
EPSS Средний

Описание

A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This vulnerability is due to an insecure default configuration of the Kubernetes container management subsystem within DNA Center. An attacker who has the ability to access the Kubernetes service port could execute commands with elevated privileges within provisioned containers. A successful exploit could result in a complete compromise of affected containers. This vulnerability affects Cisco DNA Center Software Releases 1.1.3 and prior. Cisco Bug IDs: CSCvi47253.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:digital_network_architecture_center:*:*:*:*:*:*:*:*
Версия до 1.1.3 (включая)

EPSS

Процентиль: 94%
0.12546
Средний

10 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-358
CWE-358

Связанные уязвимости

CVSS3: 10
github
больше 3 лет назад

A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This vulnerability is due to an insecure default configuration of the Kubernetes container management subsystem within DNA Center. An attacker who has the ability to access the Kubernetes service port could execute commands with elevated privileges within provisioned containers. A successful exploit could result in a complete compromise of affected containers. This vulnerability affects Cisco DNA Center Software Releases 1.1.3 and prior. Cisco Bug IDs: CSCvi47253.

CVSS3: 9.8
fstec
больше 7 лет назад

Уязвимость подсистемы управления контейнерами Kubernetes системы управления сетевой инфраструктурой Cisco Digital Network Architecture Center позволяющая нарушителю обойти процедуру аутентификации и выполнить команды с повышенными привилегиями

EPSS

Процентиль: 94%
0.12546
Средний

10 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-358
CWE-358