CVE-2018-15811
KEV PoC largeWeak Encryption of Input Parameters in DotNetNuke (DNN) 9.2.x
CISA: DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
DotNetNuke (DNN) 9.2 through 9.2.1 uses an inadequate (weak) encryption algorithm and strength to protect encrypted input parameters, classified under CWE-326. An unauthenticated remote attacker can exploit the weak cryptography to decrypt or forge these protected parameters; combined with the publicly documented cookie deserialization issue, this can lead to remote code execution on affected DNN servers. The CVSS score of 7.5 (High) with a network, no-privilege, no-user-interaction vector reflects unauthenticated remote exposure with high confidentiality impact. All deployments running DNN versions 9.2 through 9.2.1 are affected. Exploitation is confirmed in the wild: the issue is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and EPSS assigns a 74% probability of exploitation within 30 days.
What to do: Apply the vendor's update to any DotNetNuke release later than 9.2.1 as required by CISA's KEV catalog; do not remain on 9.2.x. Verify DNN version in use, review logs for forged or anomalous cookies/viewstate parameters, and consider temporarily restricting unauthenticated access to DNN portals until patched.
| DNN Corp (dnnsoftware) DotNetNuke (DNN) CMS | 9.2 through 9.2.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
- Affected
- DotNetNuke (DNN) DotNetNuke (DNN)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- dnnsoftware
- Products
- dotnetnuke
- Weakness
- CWE-326
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.