← Vulnerability feed

Vulnerability record · CVE-2018-0268 · published 17 May 2018

CVE-2018-0268: Cisco digital network architecture center vulnerability

Cisco · Digital Network Architecture Center

A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This vulnerability is due to an insecure default configuration of the Kubernetes container management subsystem within DNA Center. An attacker who has the ability to access the Kubernetes service port could execute commands with elevated privileges within provisioned containers. A successful exploit could result in a complete compromise of affected containers. This vulnerability affects Cisco DNA Center Software Releases 1.1.3 and prior. Cisco Bug IDs: CSCvi47253.

10.0 CVSS 3.0 Critical EPSS 5.0% · top 8.1% CWE-358 · CWE-358
10.0CVSS 3.0 base score, v2 10.0
5.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This vulnerability is due to an insecure default configuration of the Kubernetes container management subsystem within DNA Center. An attacker who has the ability to access the Kubernetes service port could execute commands with elevated privileges within provisioned containers. A successful exploit could result in a complete compromise of affected containers. This vulnerability affects Cisco DNA Center Software Releases 1.1.3 and prior. Cisco Bug IDs: CSCvi47253.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0268 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2018-0222Cisco digital network architecture center hard-coded credentials vulnerabilityA vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by…EPSS 3.6%9.8CVE-2018-15386Cisco digital network architecture center vulnerabilityA vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and have …EPSS 3.4%9.8CVE-2018-0448Cisco digital network architecture center inadequate encryption strength vulnerabilityA vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker…EPSS 2.1%9.8CVE-2018-0271Cisco digital network architecture center improper authentication vulnerabilityA vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass a…EPSS 2.5%9.3CVE-2019-1848Cisco digital network architecture center exposure of resource to wrong sphere vulnerabilityA vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and acc…EPSS 0.73%8.8CVE-2020-3281Cisco digital network architecture center sensitive information in log file vulnerabilityA vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to vi…EPSS 1.0%7.5CVE-2019-1675Cisco aironet active sensor hard-coded credentials vulnerabilityA vulnerability in the default configuration of the Cisco Aironet Active Sensor could allow an unauthenticated, remote attacker to restart the sensor…EPSS 2.6%7.5CVE-2018-5390Linux kernel TCP out-of-order queue processing denial of serviceLinux kernel versions 4.9 and later can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incomi…EPSS 74%analysed

Source: NIST National Vulnerability Database (record CVE-2018-0268), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.