PT-2019-2437 · Cisco · Cisco Dna Center

Publicado

2019-06-19

·

Atualizado

2019-10-09

·

CVE-2019-1848

CVSS v3.1

9.3

Crítica

VetorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Digital Network Architecture (DNA) Center (affected versions not specified)
Description The issue is related to insufficient access restriction to ports necessary for system operation. This could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. An attacker could exploit this by connecting an unauthorized network device to the subnet designated for cluster services, potentially reaching internal services that are not hardened for external access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02215
CVE-2019-1848

Produtos afetados

Cisco Dna Center