Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-15394

Опубликовано: 08 нояб. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected system. The vulnerability is due to an insecure system configuration. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. An exploit could allow the attacker to gain unauthenticated access, resulting in elevated privileges in the SMC.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:stealthwatch_enterprise:*:*:*:*:*:*:*:*
Версия до 6.10.2 (включая)

EPSS

Процентиль: 34%
0.00141
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-284
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected system. The vulnerability is due to an insecure system configuration. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. An exploit could allow the attacker to gain unauthenticated access, resulting in elevated privileges in the SMC.

CVSS3: 9.8
fstec
больше 7 лет назад

Уязвимость консоли управления Stealthwatch Management Console (SMC) системы анализа и обнаружения угроз Cisco Stealthwatch Enterprise, позволяющая нарушителю обойти процедуру аутентификации и выполнить произвольный код с привилегиями администратора

EPSS

Процентиль: 34%
0.00141
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-284
NVD-CWE-noinfo