7.4
CVE-2018-0434
- EPSS 0.13%
- Veröffentlicht 05.10.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:38:13
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the Zero Touch Provisioning feature of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Vedge 100 Firmware Version < 18.3.0
Cisco ≫ Vedge 1000 Firmware Version < 18.3.0
Cisco ≫ Vedge 2000 Firmware Version < 18.3.0
Cisco ≫ Vedge 5000 Firmware Version < 18.3.0
Cisco ≫ Vmanage Network Management System Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.13% | 0.325 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.4 | 2.2 | 5.2 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.