CVE-2018-0222 is a critical vulnerability in Cisco Digital Network Architecture (DNA) Center, affecting all releases prior to 1.1.3. It stems from undocumented, static administrative credentials, allowing an unauthenticated, remote attacker to log in and execute arbitrary commands with root privileges. With a CVSS score of 10.0, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, it has garnered significant community attention with 12 mentions and two media articles highlighting the hardcoded password issue. There is no publicly available exploit code in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.3CPE matchmatch criteria | cpe:2.3:a:cisco:digital_network_architecture_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.