CVE-2018-0376
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to access the Policy Builder interface. The vulnerability is due to a lack of authentication. An attacker could exploit this vulnerability by accessing the Policy Builder interface. A successful exploit could allow the attacker to make changes to existing repositories and create new repositories. Cisco Bug IDs: CSCvi35109.
Una vulnerabilidad en la la interfaz Policy Builder de Cisco Policy Suite en versiones anteriores a la 18.2.0 podría permitir que un atacante remoto no autenticado acceda a la interfaz de Policy Builder. Esta vulnerabilidad se debe a la ausencia de autenticación. Un atacante podría explotar esta vulnerabilidad accediendo a la interfaz Policy Builder. Su explotación con éxito podría permitir que el atacante realice cambios en repositorios existentes y creen nuevos repositorios. Cisco Bug IDs: CSCvi35109.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-27 CVE Reserved
- 2018-07-18 CVE Published
- 2023-12-09 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/104849 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Mobility Services Engine Search vendor "Cisco" for product "Mobility Services Engine" | 18.0.0 Search vendor "Cisco" for product "Mobility Services Engine" and version "18.0.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Policy Suite Search vendor "Cisco" for product "Policy Suite" | < 18.2.0 Search vendor "Cisco" for product "Policy Suite" and version " < 18.2.0" | - |
Affected
|