CVE-2018-0269

MEDIUM

Cisco Digital Network Architecture Center - Unauthenticated Sensitive Information Exposure via CORS Misconfiguration

Title source: llm
STIX 2.1

Description

A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerability is due to an overly permissive Cross Origin Resource Sharing (CORS) policy. An attacker could exploit this vulnerability by convincing a user to follow a malicious link. An exploit could allow the attacker to communicate with the API and exfiltrate sensitive information. Cisco Bug IDs: CSCvh99208.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103950

Scores

CVSS v3 4.3
EPSS 0.0132
EPSS Percentile 67.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-863
Status published
Products (1)
cisco/digital_network_architecture_center 1.1
Published Apr 19, 2018
Tracked Since Feb 18, 2026