CVE-2018-18325
KEV PoC largeUnauthenticated deserialization RCE via weak encryption in DotNetNuke 9.2-9.2.2
CISA: DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
DNN (DotNetNuke) 9.2 through 9.2.2 protects input parameters, including the cookie values used for authentication state, with an encryption algorithm that is too weak; this flaw exists because the earlier fix for CVE-2018-15811 was incomplete. A remote, unauthenticated attacker can abuse the inadequate cryptography to forge or tamper with encrypted parameter values, which the application then deserializes, bypassing the original patch. Successful exploitation exposes sensitive information and, as demonstrated by the public cookie-deserialization exploit, can lead to full remote code execution on the web server. Any organization running DNN 9.2 through 9.2.2, typically as a public-facing .NET CMS website, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 and carries a 74% EPSS probability of exploitation in the next 30 days (99th percentile).
What to do: Upgrade DNN to the updated 9.2.2 release that completes the CVE-2018-15811 fix, or to a later supported version, following vendor update instructions; this is a CISA KEV item, so patching is urgent. Verify the exact version deployed, since sites on the original 9.2.2 build may still lack the complete fix, and until patched, restrict internet exposure of the site and monitor for exploitation of the cookie deserialization path.
| dnnsoftware dotnetnuke | 9.2 through 9.2.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
- Affected
- DotNetNuke (DNN) DotNetNuke (DNN)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- dnnsoftware
- Products
- dotnetnuke
- Weakness
- CWE-326
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.