CVE-2018-0368 is a sensitive information disclosure vulnerability in Cisco Digital Network Architecture (DNA) Center, specifically affecting the Application Policy Infrastructure Controller Enterprise Module. An authenticated, local attacker can exploit insufficient security restrictions to access unprotected log files. This allows for the retrieval of sensitive information, potentially including system credentials, resulting in a high severity CVSS score of 7.8. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1_baseCPE matchmatch criteria | cpe:2.3:a:cisco:application_policy_infrastructure_controller_enterprise_module:1.1_base:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.