CVE-2018-0271 describes a critical authentication bypass vulnerability in the API gateway of Cisco Digital Network Architecture (DNA) Center software releases prior to 1.1.2. This flaw, caused by improper URL normalization, allows an unauthenticated, remote attacker to gain elevated privileges by accessing critical services. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness despite its inactive status on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.2CPE matchmatch criteria | cpe:2.3:a:cisco:digital_network_architecture_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.