CVE-2018-0222
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by using an administrative account that has default, static user credentials.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by using an administrative account that has default, static user credentials. The vulnerability is due to the presence of undocumented, static user credentials for the default administrative account for the affected software. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands with root privileges. This vulnerability affects all releases of Cisco DNA Center Software prior to Release 1.1.3. Cisco Bug IDs: CSCvh98929.
- CVSS 3.0
- 10.0 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 3.74% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- cisco/digital network architecture center
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/104193Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180516-dnacVendor Advisory
- http://www.securityfocus.com/bid/104193Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180516-dnacVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.