Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-0448

Опубликовано: 05 окт. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due to insufficient security restrictions for critical management functions. An attacker could exploit this vulnerability by sending a valid identity management request to the affected system. An exploit could allow the attacker to view and make unauthorized modifications to existing system users as well as create new users.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:digital_network_architecture_center:*:*:*:*:*:*:*:*
Версия до 1.1.4 (исключая)

EPSS

Процентиль: 30%
0.0011
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-326
CWE-326

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due to insufficient security restrictions for critical management functions. An attacker could exploit this vulnerability by sending a valid identity management request to the affected system. An exploit could allow the attacker to view and make unauthorized modifications to existing system users as well as create new users.

CVSS3: 9.8
fstec
больше 7 лет назад

Уязвимость службы управления идентификацией системы управления сетью Cisco Digital Network Architecture (DNA) Center, позволяющая нарушителю обойти процедуру аутентификации и получить контроль над функциями управления идентификацией

EPSS

Процентиль: 30%
0.0011
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-326
CWE-326