PT-2019-2437 · Cisco · Cisco Dna Center

Published

2019-06-19

·

Updated

2019-10-09

·

CVE-2019-1848

CVSS v3.1

9.3

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Digital Network Architecture (DNA) Center (affected versions not specified)
Description The issue is related to insufficient access restriction to ports necessary for system operation. This could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. An attacker could exploit this by connecting an unauthorized network device to the subnet designated for cluster services, potentially reaching internal services that are not hardened for external access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02215
CVE-2019-1848

Affected Products

Cisco Dna Center