PT-2018-1334 · Linux Foundation+1 · Kubernetes+1

Publicado

2018-05-16

·

Atualizado

2019-10-09

·

CVE-2018-0268

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Digital Network Architecture (DNA) Center versions 1.1.3 and prior
Description A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This issue is due to an insecure default configuration of the Kubernetes container management subsystem within DNA Center. An attacker who has access to the Kubernetes service port could execute commands with elevated privileges within provisioned containers, potentially resulting in a complete compromise of affected containers.
Recommendations For versions 1.1.3 and prior, update to a version later than 1.1.3 to resolve the issue. As a temporary workaround, consider restricting access to the Kubernetes service port to minimize the risk of exploitation. Additionally, review and secure the default configuration of the Kubernetes container management subsystem to prevent unauthorized access.

Correção

Improperly Implemented Security Check for Standard

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00832
CVE-2018-0268

Produtos afetados

Cisco Digital Network Architecture (Dna) Center
Kubernetes