cisco-sa-20180815-dna-injection: Cisco Digital Network Architecture Center Command Injection Vulnerability
A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to incorrect input validation of user-supplied data. An attacker could exploit this vulnerability by sending a malicious packet. A successful exploit could allow the attacker to execute arbitrary commands with root privileges.
There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180815-dna-injection
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20180815-dna-injection?
The severity of cisco-sa-20180815-dna-injection is rated as high due to its potential for command injection attacks.
How do I fix cisco-sa-20180815-dna-injection?
To fix cisco-sa-20180815-dna-injection, update your Cisco Digital Network Architecture Center to the latest available version.
Who is affected by cisco-sa-20180815-dna-injection?
Cisco Digital Network Architecture Center users with authenticated access are affected by cisco-sa-20180815-dna-injection.
What type of attack can exploit cisco-sa-20180815-dna-injection?
cisco-sa-20180815-dna-injection allows for command injection attacks due to improper input validation.
What versions of Cisco Digital Network Architecture Center are vulnerable to cisco-sa-20180815-dna-injection?
All versions of Cisco Digital Network Architecture Center with the vulnerable CronJob scheduler API are susceptible to cisco-sa-20180815-dna-injection.