Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-0374

Опубликовано: 18 июл. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connect directly to the Policy Builder database. The vulnerability is due to a lack of authentication. An attacker could exploit this vulnerability by connecting directly to the Policy Builder database. A successful exploit could allow the attacker to access and change any data in the Policy Builder database. Cisco Bug IDs: CSCvh06134.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:mobility_services_engine:14.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 92%
0.09023
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-306
CWE-306

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connect directly to the Policy Builder database. The vulnerability is due to a lack of authentication. An attacker could exploit this vulnerability by connecting directly to the Policy Builder database. A successful exploit could allow the attacker to access and change any data in the Policy Builder database. Cisco Bug IDs: CSCvh06134.

CVSS3: 9.8
fstec
больше 7 лет назад

Уязвимость базы данных Policy Builder программного средства управления политиками Cisco Policy Suite, позволяющая нарушителю получить доступ к базе данных и изменить произвольные данные

EPSS

Процентиль: 92%
0.09023
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-306
CWE-306