7.8
CVE-2018-0338
- EPSS 0.1%
- Published 07.06.2018 21:29:00
- Last modified 21.11.2024 03:38:00
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software lacks proper input and validation checks for certain file systems. An attacker could exploit this vulnerability by issuing crafted commands in the CLI of an affected system. A successful exploit could allow the attacker to cause other users to execute unwanted arbitrary commands on the affected system. Cisco Bug IDs: CSCvf52994.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Unified Computing System Version5.5(203)
Cisco ≫ Unified Computing System Version7.0(0)bz(0.46)
Cisco ≫ Unified Computing System Version9.0(100.20)b
Cisco ≫ Unified Computing System Version9.1(1.13)
Cisco ≫ Unified Computing System Version9.9(0.902)
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.278 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.