Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-0269

Опубликовано: 19 апр. 2018
Источник: nvd
CVSS3: 4.3
CVSS2: 4.3
EPSS Низкий

Описание

A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerability is due to an overly permissive Cross Origin Resource Sharing (CORS) policy. An attacker could exploit this vulnerability by convincing a user to follow a malicious link. An exploit could allow the attacker to communicate with the API and exfiltrate sensitive information. Cisco Bug IDs: CSCvh99208.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:digital_network_architecture_center:1.1:*:*:*:*:*:*:*

EPSS

Процентиль: 68%
0.00565
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200
CWE-863

Связанные уязвимости

CVSS3: 4.3
github
больше 3 лет назад

A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerability is due to an overly permissive Cross Origin Resource Sharing (CORS) policy. An attacker could exploit this vulnerability by convincing a user to follow a malicious link. An exploit could allow the attacker to communicate with the API and exfiltrate sensitive information. Cisco Bug IDs: CSCvh99208.

EPSS

Процентиль: 68%
0.00565
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200
CWE-863