Evidence used
- No CISA KEV confirmation is currently recorded.
- EPSS is 0.73% for the current model date.
BlackTreeCVE IntelligenceCisco · Cisco Digital Network Architecture Center (DNA Center)
Official source article: Cisco CISCO-SA-20190619-DNAC-BYPASS ↗. Check the applicable product and release in the original source.
Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.
Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.
Fix not verifiedA vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports necessary for system operation. An attacker could exploit this vulnerability by connecting an unauthorized network device to the subnet designated for cluster services. A successful exploit could allow an attacker to reach internal services that are not hardened for external access.
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports necessary for system operation. An attacker could exploit this vulnerability by connecting an unauthorized network device to the subnet designated for cluster services. A successful exploit could allow an attacker to reach internal services that are not hardened for external access.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
An attacker operating through an adjacent network may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports necessary for system operation. An attacker could exploit this vulnerability by connecting an unauthorized network device to the subnet designated for cluster services. A successful exploit could allow an attacker to reach internal services that are not hardened for external access.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
An attacker operating through an adjacent network may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.
No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.
CWE-668: Exposure of Resource to Wrong Sphere. The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:NCommon Vulnerability Scoring System 3.0: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Published 20 Jun 2019 · Last source change 20 Nov 2024, 17:17 UTC · CWE-668 · Exposure of Resource to Wrong Sphere
Core structured fields are present and their contributing authorities are shown above.