Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-15380

Опубликовано: 20 фев. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 8.3
EPSS Низкий

Описание

A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by connecting to the cluster service manager and injecting commands into the bound process. A successful exploit could allow the attacker to run commands on the affected host as the root user. This vulnerability affects Cisco HyperFlex Software releases prior to 3.5(2a).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:hyperflex_hx_data_platform:3.0\(1a\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:hyperflex_hx_data_platform:3.5\(1a\):*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00165
Низкий

8.8 High

CVSS3

8.3 High

CVSS2

Дефекты

CWE-78
CWE-78

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by connecting to the cluster service manager and injecting commands into the bound process. A successful exploit could allow the attacker to run commands on the affected host as the root user. This vulnerability affects Cisco HyperFlex Software releases prior to 3.5(2a).

CVSS3: 8.8
fstec
почти 7 лет назад

Уязвимость компонента cluster service manager гиперконвергентной инфраструктуры Cisco HyperFlex, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 38%
0.00165
Низкий

8.8 High

CVSS3

8.3 High

CVSS2

Дефекты

CWE-78
CWE-78