Critical severity9.8NVD Advisory· Published Oct 5, 2018· Updated Jun 17, 2026
CVE-2018-0448
CVE-2018-0448
Description
A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due to insufficient security restrictions for critical management functions. An attacker could exploit this vulnerability by sending a valid identity management request to the affected system. An exploit could allow the attacker to view and make unauthorized modifications to existing system users as well as create new users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:cisco:digital_network_architecture_center:*:*:*:*:*:*:*:*Range: <1.1.4
(expand)+ 1 more
- (no CPE)
- (no CPE)range: n/a
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/105502nvdThird Party AdvisoryVDB Entry
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181003-dna-auth-bypassnvdVendor Advisory
News mentions
0No linked articles in our index yet.