PT-2018-1334 · Linux Foundation+1 · Kubernetes+1

Published

2018-05-16

·

Updated

2019-10-09

·

CVE-2018-0268

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Digital Network Architecture (DNA) Center versions 1.1.3 and prior
Description A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This issue is due to an insecure default configuration of the Kubernetes container management subsystem within DNA Center. An attacker who has access to the Kubernetes service port could execute commands with elevated privileges within provisioned containers, potentially resulting in a complete compromise of affected containers.
Recommendations For versions 1.1.3 and prior, update to a version later than 1.1.3 to resolve the issue. As a temporary workaround, consider restricting access to the Kubernetes service port to minimize the risk of exploitation. Additionally, review and secure the default configuration of the Kubernetes container management subsystem to prevent unauthorized access.

Fix

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00832
CVE-2018-0268

Affected Products

Cisco Digital Network Architecture (Dna) Center
Kubernetes