ZeroHour

CVE-2018-18325

KEV PoC large

Unauthenticated deserialization RCE via weak encryption in DotNetNuke 9.2-9.2.2

CISA: DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

CVSS 3.1
7.5 high
EPSS
74%p99
Published
()
KEV added
AI analysis

DNN (DotNetNuke) 9.2 through 9.2.2 protects input parameters, including the cookie values used for authentication state, with an encryption algorithm that is too weak; this flaw exists because the earlier fix for CVE-2018-15811 was incomplete. A remote, unauthenticated attacker can abuse the inadequate cryptography to forge or tamper with encrypted parameter values, which the application then deserializes, bypassing the original patch. Successful exploitation exposes sensitive information and, as demonstrated by the public cookie-deserialization exploit, can lead to full remote code execution on the web server. Any organization running DNN 9.2 through 9.2.2, typically as a public-facing .NET CMS website, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 and carries a 74% EPSS probability of exploitation in the next 30 days (99th percentile).

What to do: Upgrade DNN to the updated 9.2.2 release that completes the CVE-2018-15811 fix, or to a later supported version, following vendor update instructions; this is a CISA KEV item, so patching is urgent. Verify the exact version deployed, since sites on the original 9.2.2 build may still lack the complete fix, and until patched, restrict internet exposure of the site and monitor for exploitation of the cookie deserialization path.

Affected
dnnsoftware dotnetnuke9.2 through 9.2.2
Estimated exposure
largetens of thousands of internet-exposed DNN sites — DotNetNuke has historically powered hundreds of thousands of websites per public web-technology surveys, and only the brief 9.2-9.2.2 release window carries the flaw, so the residue of still-unpatched installations is plausibly in the tens…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.

CISA Known Exploited Vulnerability
Affected
DotNetNuke (DNN) DotNetNuke (DNN)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
dnnsoftware
Products
dotnetnuke
Weakness
CWE-326
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.