cisco-sa-20181003-dna-auth-bypass: Cisco Digital Network Architecture Center Authentication Bypass Vulnerability
A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due to insufficient security restrictions for critical management functions. An attacker could exploit this vulnerability by sending a valid identity management request to the affected system. An exploit could allow the attacker to view and make unauthorized modifications to existing system users as well as create new users.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-dna-auth-bypass
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20181003-dna-auth-bypass?
The severity of cisco-sa-20181003-dna-auth-bypass is considered high due to the potential for unauthorized access to identity management functions.
How do I fix cisco-sa-20181003-dna-auth-bypass?
To fix cisco-sa-20181003-dna-auth-bypass, it is recommended to apply the latest security updates provided by Cisco for the Digital Network Architecture Center.
What causes cisco-sa-20181003-dna-auth-bypass?
cisco-sa-20181003-dna-auth-bypass is caused by insufficient security measures in the identity management service of Cisco DNA Center.
Who is affected by cisco-sa-20181003-dna-auth-bypass?
The vulnerability cisco-sa-20181003-dna-auth-bypass affects users of Cisco Digital Network Architecture Center.
What type of attack can cisco-sa-20181003-dna-auth-bypass facilitate?
cisco-sa-20181003-dna-auth-bypass can facilitate a remote attacker to bypass authentication and gain complete control over identity management functions.