A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due to insufficient security restrictions for critical management functions. An attacker could exploit this vulnerability by sending a valid identity management request to the affected system. An exploit could allow the attacker to view and make unauthorized modifications to existing system users as well as create new users.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCisco Digital Network Architecture Center
APPCisco< 1.1.4
Related vulnerabilities
Cisco DNA Center — pominięcie uwierzytelnienia do wewnętrznych usług klastra
Cisco DNA Center — pominięcie uwierzytelnienia przez domyślną konfigurację
Cisco DNA Center — pominięcie uwierzytelnienia w bramie API (Auth Bypass)
Cisco DNA Center — pominięcie uwierzytelnienia w podsystemie Kubernetes
Cisco DNA Center — statyczne dane uwierzytelniające konta administratora