PT-2018-1334 · Linux Foundation+1 · Kubernetes+1
Publicado
2018-05-16
·
Atualizado
2019-10-09
·
CVE-2018-0268
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Digital Network Architecture (DNA) Center versions 1.1.3 and prior
Description
A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This issue is due to an insecure default configuration of the Kubernetes container management subsystem within DNA Center. An attacker who has access to the Kubernetes service port could execute commands with elevated privileges within provisioned containers, potentially resulting in a complete compromise of affected containers.
Recommendations
For versions 1.1.3 and prior, update to a version later than 1.1.3 to resolve the issue. As a temporary workaround, consider restricting access to the Kubernetes service port to minimize the risk of exploitation. Additionally, review and secure the default configuration of the Kubernetes container management subsystem to prevent unauthorized access.
Correção
Improperly Implemented Security Check for Standard
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Digital Network Architecture (Dna) Center
Kubernetes