CVE-2018-0222
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by using an administrative account that has default, static user credentials. The vulnerability is due to the presence of undocumented, static user credentials for the default administrative account for the affected software. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands with root privileges. This vulnerability affects all releases of Cisco DNA Center Software prior to Release 1.1.3. Cisco Bug IDs: CSCvh98929.
Una vulnerabilidad en Cisco Digital Network Architecture (DNA) Center podría permitir que un atacante remoto no autenticado inicie sesión en un sistema afectado mediante el uso de una cuenta administrativa que tiene credenciales de usuario estáticas por defecto. La vulnerabilidad se debe a la presencia de credenciales de usuario estáticas por defecto no documentadas para la cuenta administrativa del software afectado. Un atacante podría explotar esta vulnerabilidad empleando la cuenta para iniciar sesión en un sistema afectado. Su explotación con éxito podría permitir que el atacante consiga iniciar sesión en el sistema afectado y ejecute comandos arbitrarios con privilegios root. Esta vulnerabilidad afecta a todas las distribuciones de Cisco DNA Center Software anteriores a Release 1.1.3. Cisco Bug IDs: CSCvh98929.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-27 CVE Reserved
- 2018-05-17 CVE Published
- 2023-10-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/104193 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180516-dnac | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Digital Network Architecture Center Search vendor "Cisco" for product "Digital Network Architecture Center" | < 1.1.3 Search vendor "Cisco" for product "Digital Network Architecture Center" and version " < 1.1.3" | - |
Affected
|