ZeroHour

CVE-2018-15811

KEV PoC large

Weak Encryption of Input Parameters in DotNetNuke (DNN) 9.2.x

CISA: DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

CVSS 3.1
7.5 high
EPSS
74%p99
Published
()
KEV added
AI analysis

DotNetNuke (DNN) 9.2 through 9.2.1 uses an inadequate (weak) encryption algorithm and strength to protect encrypted input parameters, classified under CWE-326. An unauthenticated remote attacker can exploit the weak cryptography to decrypt or forge these protected parameters; combined with the publicly documented cookie deserialization issue, this can lead to remote code execution on affected DNN servers. The CVSS score of 7.5 (High) with a network, no-privilege, no-user-interaction vector reflects unauthenticated remote exposure with high confidentiality impact. All deployments running DNN versions 9.2 through 9.2.1 are affected. Exploitation is confirmed in the wild: the issue is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and EPSS assigns a 74% probability of exploitation within 30 days.

What to do: Apply the vendor's update to any DotNetNuke release later than 9.2.1 as required by CISA's KEV catalog; do not remain on 9.2.x. Verify DNN version in use, review logs for forged or anomalous cookies/viewstate parameters, and consider temporarily restricting unauthenticated access to DNN portals until patched.

Affected
DNN Corp (dnnsoftware) DotNetNuke (DNN) CMS9.2 through 9.2.1
Estimated exposure
largeorder of magnitude ~10,000–100,000 internet-exposed DNN sites (exact count unknown) — DNN is a widely deployed ASP.NET CMS with hundreds of thousands of historical site deployments, and public internet scans typically show tens of thousands of exposed DNN instances, though the narrow 9.2–9.2.1 version window makes the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

CISA Known Exploited Vulnerability
Affected
DotNetNuke (DNN) DotNetNuke (DNN)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
dnnsoftware
Products
dotnetnuke
Weakness
CWE-326
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.