CVE-2019-1848
published 2019-06-20CVE-2019-1848: A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access…
PriorityP354critical9.3CVSS 3.0
AVAACLPRNUINSCCHIHAN
EPSS
0.73%
50.1th percentile
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports necessary for system operation. An attacker could exploit this vulnerability by connecting an unauthorized network device to the subnet designated for cluster services. A successful exploit could allow an attacker to reach internal services that are not hardened for external access.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_digital_network_architecture_center | >= unspecified < 1.3 | 1.3 |
| cisco | digital_network_architecture_center | < 1.3 | 1.3 |
| cisco | dna_center | — | — |
CVSS provenance
nvdv3.09.3CRITICALCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
nvdv2.04.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-72v5-4c4w-2chj: A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and acce
ghsa_unreviewed·2022-05-24
CVE-2019-1848 [CRITICAL] CWE-668 GHSA-72v5-4c4w-2chj: A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and acce
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports necessary for system operation. An attacker could exploit this vulnerability by connecting an unauthorized network device to the subnet designated for cluster services. A successful exploit could allow an attacker to reach internal services that are not hardened for external access.
Cisco
Cisco DNA Center Authentication Bypass Vulnerability
vendor_cisco·2019-06-19·CVSS 9.3
CVE-2019-1848 [CRITICAL] CWE-668 Cisco DNA Center Authentication Bypass Vulnerability
Cisco DNA Center Authentication Bypass Vulnerability
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services.
The vulnerability is due to insufficient access restriction to ports necessary for system operation. An attacker could exploit this vulnerability by connecting an unauthorized network device to the subnet designated for cluster services. A successful exploit could allow an attacker to reach internal services that are not hardened for external access.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/sec
Cisco
Cisco DNA Center Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1848 Cisco DNA Center Authentication Bypass Vulnerability
CVE-2019-1848: Cisco DNA Center Authentication Bypass Vulnerability
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports necessary for system operation. An attacker could exploit this vulnerability by connecting an unauthorized network device to the subnet designated for cluster services. A successful exploit could allow an attacker to reach internal services that are not hardened for external access. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-668, CWE-668
Bug IDs: CSCvj03748
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-20
Published