Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-15382

Опубликовано: 05 окт. 2018
Источник: nvd
CVSS3: 8.6
CVSS2: 7.5
EPSS Низкий

Описание

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerability is due to a static signing key that is present in all Cisco HyperFlex systems. An attacker could exploit this vulnerability by accessing the static signing key from one HyperFlex system and using it to generate valid, signed session tokens for another HyperFlex system. A successful exploit could allow the attacker to access the HyperFlex Web UI of a system for which they are not authorized.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:cisco:hyperflex_hx_data_platform:3.0\(1a\):*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00676
Низкий

8.6 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-642
CWE-642

Связанные уязвимости

CVSS3: 8.6
github
больше 3 лет назад

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerability is due to a static signing key that is present in all Cisco HyperFlex systems. An attacker could exploit this vulnerability by accessing the static signing key from one HyperFlex system and using it to generate valid, signed session tokens for another HyperFlex system. A successful exploit could allow the attacker to access the HyperFlex Web UI of a system for which they are not authorized.

CVSS3: 8.6
fstec
больше 7 лет назад

Уязвимость гиперконвергентной инфраструктуры Cisco HyperFlex, связанная с небезопасным внешним контролем за критическими данными состояния, позволяющая нарушителю создать действительные подписанные токены сеанса и повысить свои привилегии

EPSS

Процентиль: 71%
0.00676
Низкий

8.6 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-642
CWE-642