Medium severity4.3NVD Advisory· Published Apr 19, 2018· Updated Jun 17, 2026
CVE-2018-0269
CVE-2018-0269
Description
A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerability is due to an overly permissive Cross Origin Resource Sharing (CORS) policy. An attacker could exploit this vulnerability by convincing a user to follow a malicious link. An exploit could allow the attacker to communicate with the API and exfiltrate sensitive information. Cisco Bug IDs: CSCvh99208.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:cisco:digital_network_architecture_center:1.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/103950nvdThird Party AdvisoryVDB Entry
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-dna1nvdVendor Advisory
News mentions
0No linked articles in our index yet.