CVE-2018-0440 describes a critical vulnerability in the web interface of Cisco Data Center Network Manager (DCNM). This flaw, stemming from incomplete input validation, allows an authenticated application administrator to execute arbitrary commands with root privileges on the underlying operating system. The attack requires high privileges (PR:H) but has low attack complexity (AC:L), leading to a CVSS score of 7.2 (HIGH) due to complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence like Metasploit or ExploitDB entries exist, the vulnerability received some community discussion and media coverage, indicating awareness, though it is not currently listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.0\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:data_center_network_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.