Authentication bypass in Cisco Unified Computing E-Series Servers and Cisco 5000 Series Enterprise Network Compute System - CVE-2018-0362
Published: June 20, 2018 / Updated: June 21, 2018
Cisco Unified Computing E-Series Servers
Cisco 5000 Series Enterprise Network Compute System
Detailed vulnerability description
The vulnerability allows a local unauthenticated attacker to bypass authentication on the target system.
The vulnerability exists in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers due to improper security restrictions. A local attacker can submit an empty password value to an affected device's BIOS authentication prompt, bypass authentication and gain access to a restricted set of user-level BIOS commands.