7.2
CVE-2018-0294
- EPSS 0.26%
- Published 20.06.2018 21:29:00
- Last modified 21.11.2024 03:37:54
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure an unauthorized administrator account for an affected device. The vulnerability exists because the affected software does not properly delete sensitive files when certain CLI commands are used to clear the device configuration and reload a device. An attacker could exploit this vulnerability by logging into an affected device as an administrative user and configuring an unauthorized account for the device. The account would not require a password for authentication and would be accessible only via a Secure Shell (SSH) connection to the device. A successful exploit could allow the attacker to configure an unauthorized account that has administrative privileges, does not require a password for authentication, and does not appear in the running configuration or the audit logs for the affected device. This vulnerability affects Firepower 4100 Series Next-Generation Firewalls, Firepower 9300 Security Appliance, Nexus 1000V Series Switches, Nexus 1100 Series Cloud Services Platforms, Nexus 2000 Series Fabric Extenders, Nexus 3500 Platform Switches, Nexus 4000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCvd13993, CSCvd34845, CSCvd34857, CSCvd34862, CSCvd34879, CSCve35753.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Nx-os Version7.3(2)n1(0.354)
Cisco ≫ Nexus 5000 Version-
Cisco ≫ Nexus 5010 Version-
Cisco ≫ Nexus 5020 Version-
Cisco ≫ Nexus 5548p Version-
Cisco ≫ Nexus 5548up Version-
Cisco ≫ Nexus 5596t Version-
Cisco ≫ Nexus 5596up Version-
Cisco ≫ Nexus 56128p Version-
Cisco ≫ Nexus 5624q Version-
Cisco ≫ Nexus 5648q Version-
Cisco ≫ Nexus 5672up Version-
Cisco ≫ Nexus 5696q Version-
Cisco ≫ Nexus 5010 Version-
Cisco ≫ Nexus 5020 Version-
Cisco ≫ Nexus 5548p Version-
Cisco ≫ Nexus 5548up Version-
Cisco ≫ Nexus 5596t Version-
Cisco ≫ Nexus 5596up Version-
Cisco ≫ Nexus 56128p Version-
Cisco ≫ Nexus 5624q Version-
Cisco ≫ Nexus 5648q Version-
Cisco ≫ Nexus 5672up Version-
Cisco ≫ Nexus 5696q Version-
Cisco ≫ Nx-os Version8.8(3.5)s0
Cisco ≫ Nexus 92160yc-x Version-
Cisco ≫ Nexus 92304qc Version-
Cisco ≫ Nexus 9236c Version-
Cisco ≫ Nexus 9272q Version-
Cisco ≫ Nexus 93108tc-ex Version-
Cisco ≫ Nexus 93120tx Version-
Cisco ≫ Nexus 93128tx Version-
Cisco ≫ Nexus 93180yc-ex Version-
Cisco ≫ Nexus 9332pq Version-
Cisco ≫ Nexus 9372px Version-
Cisco ≫ Nexus 9372tx Version-
Cisco ≫ Nexus 9396px Version-
Cisco ≫ Nexus 9396tx Version-
Cisco ≫ Nexus 9504 Version-
Cisco ≫ Nexus 9508 Version-
Cisco ≫ Nexus 9516 Version-
Cisco ≫ Nexus N9k-c9508-fm-r Version-
Cisco ≫ Nexus N9k-x9636c-r Version-
Cisco ≫ Nexus N9k-x9636q-r Version-
Cisco ≫ Nexus 92304qc Version-
Cisco ≫ Nexus 9236c Version-
Cisco ≫ Nexus 9272q Version-
Cisco ≫ Nexus 93108tc-ex Version-
Cisco ≫ Nexus 93120tx Version-
Cisco ≫ Nexus 93128tx Version-
Cisco ≫ Nexus 93180yc-ex Version-
Cisco ≫ Nexus 9332pq Version-
Cisco ≫ Nexus 9372px Version-
Cisco ≫ Nexus 9372tx Version-
Cisco ≫ Nexus 9396px Version-
Cisco ≫ Nexus 9396tx Version-
Cisco ≫ Nexus 9504 Version-
Cisco ≫ Nexus 9508 Version-
Cisco ≫ Nexus 9516 Version-
Cisco ≫ Nexus N9k-c9508-fm-r Version-
Cisco ≫ Nexus N9k-x9636c-r Version-
Cisco ≫ Nexus N9k-x9636q-r Version-
Cisco ≫ Nx-os Version7.0(3)i2(4a)
Cisco ≫ Nexus 172tq-xl Version-
Cisco ≫ Nexus 3016 Version-
Cisco ≫ Nexus 3048 Version-
Cisco ≫ Nexus 3064-32t Version-
Cisco ≫ Nexus 3064-t Version-
Cisco ≫ Nexus 3064-x Version-
Cisco ≫ Nexus 3100-v Version-
Cisco ≫ Nexus 31128pq Version-
Cisco ≫ Nexus 3132c-z Version-
Cisco ≫ Nexus 3132q Version-
Cisco ≫ Nexus 3132q-x Version-
Cisco ≫ Nexus 3132q-xl Version-
Cisco ≫ Nexus 3164q Version-
Cisco ≫ Nexus 3172pq Version-
Cisco ≫ Nexus 3172pq-xl Version-
Cisco ≫ Nexus 3172tq Version-
Cisco ≫ Nexus 3172tq-32t Version-
Cisco ≫ Nexus 3232c Version-
Cisco ≫ Nexus 3264c-e Version-
Cisco ≫ Nexus 3264q Version-
Cisco ≫ Nexus 34180yc Version-
Cisco ≫ Nexus 3524-x Version-
Cisco ≫ Nexus 3524-xl Version-
Cisco ≫ Nexus 3548 Version-
Cisco ≫ Nexus 3548-x Version-
Cisco ≫ Nexus 3548-xl Version-
Cisco ≫ Nexus 3636c-r Version-
Cisco ≫ Nexus C36180yc-r Version-
Cisco ≫ Nexus 3016 Version-
Cisco ≫ Nexus 3048 Version-
Cisco ≫ Nexus 3064-32t Version-
Cisco ≫ Nexus 3064-t Version-
Cisco ≫ Nexus 3064-x Version-
Cisco ≫ Nexus 3100-v Version-
Cisco ≫ Nexus 31128pq Version-
Cisco ≫ Nexus 3132c-z Version-
Cisco ≫ Nexus 3132q Version-
Cisco ≫ Nexus 3132q-x Version-
Cisco ≫ Nexus 3132q-xl Version-
Cisco ≫ Nexus 3164q Version-
Cisco ≫ Nexus 3172pq Version-
Cisco ≫ Nexus 3172pq-xl Version-
Cisco ≫ Nexus 3172tq Version-
Cisco ≫ Nexus 3172tq-32t Version-
Cisco ≫ Nexus 3232c Version-
Cisco ≫ Nexus 3264c-e Version-
Cisco ≫ Nexus 3264q Version-
Cisco ≫ Nexus 34180yc Version-
Cisco ≫ Nexus 3524-x Version-
Cisco ≫ Nexus 3524-xl Version-
Cisco ≫ Nexus 3548 Version-
Cisco ≫ Nexus 3548-x Version-
Cisco ≫ Nexus 3548-xl Version-
Cisco ≫ Nexus 3636c-r Version-
Cisco ≫ Nexus C36180yc-r Version-
Cisco ≫ Nx-os Version7.0(3)i2(4a)
Cisco ≫ Ucs 6120xp Version-
Cisco ≫ Ucs 6140xp Version-
Cisco ≫ Ucs 6248up Version-
Cisco ≫ Ucs 6296up Version-
Cisco ≫ Ucs 6324 Version-
Cisco ≫ Ucs 6332 Version-
Cisco ≫ Ucs 6140xp Version-
Cisco ≫ Ucs 6248up Version-
Cisco ≫ Ucs 6296up Version-
Cisco ≫ Ucs 6324 Version-
Cisco ≫ Ucs 6332 Version-
Cisco ≫ Firepower Extensible Operating System Version >= 2.1.1 < 2.1.1.86
Cisco ≫ Firepower 4110 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower Extensible Operating System Version >= 2.2 < 2.2.2.17
Cisco ≫ Firepower 4110 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Fxos Version >= 1.1 < 2.0.1.159
Cisco ≫ Firepower 4110 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower Extensible Operating System Version >= 2.1.1 < 2.1.1.86
Cisco ≫ Firepower Extensible Operating System Version >= 2.2 < 2.2.2.17
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.26% | 0.487 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|