890
VMScore

CVE-2018-0375

Published: 18/07/2018 Updated: 09/10/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability in the Cluster Manager of Cisco Policy Suite prior to 18.2.0 could allow an unauthenticated, remote malicious user to log in to an affected system using the root account, which has default, static user credentials. The vulnerability is due to the presence of undocumented, static user credentials for the root account. An attacker could exploit this vulnerability by using the account to log in to an affected system. An exploit could allow the malicious user to log in to the affected system and execute arbitrary commands as the root user. Cisco Bug IDs: CSCvh02680.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco policy suite

cisco mobility services engine 14.0.0

Vendor Advisories

A vulnerability in the Cluster Manager of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system using the root account, which has default, static user credentials The vulnerability is due to the presence of undocumented, static user credentials for the root account An attacker could exploit this vulner ...