PT-2018-1334 · Linux Foundation+1 · Kubernetes+1
Published
2018-05-16
·
Updated
2019-10-09
·
CVE-2018-0268
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Digital Network Architecture (DNA) Center versions 1.1.3 and prior
Description
A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This issue is due to an insecure default configuration of the Kubernetes container management subsystem within DNA Center. An attacker who has access to the Kubernetes service port could execute commands with elevated privileges within provisioned containers, potentially resulting in a complete compromise of affected containers.
Recommendations
For versions 1.1.3 and prior, update to a version later than 1.1.3 to resolve the issue. As a temporary workaround, consider restricting access to the Kubernetes service port to minimize the risk of exploitation. Additionally, review and secure the default configuration of the Kubernetes container management subsystem to prevent unauthorized access.
Fix
Improperly Implemented Security Check for Standard
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Digital Network Architecture (Dna) Center
Kubernetes