Buffer overflow in Cisco Systems, Inc products - CVE-2018-6242

 

Buffer overflow in Cisco Systems, Inc products - CVE-2018-6242

Published: June 20, 2018 / Updated: January 4, 2026


Vulnerability identifier: #VU13416
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6242
CWE-ID: CWE-120
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a physical attacker to gain elevated privileges on the target system.

The vulnerability exists due to a buffer overflow vulnerability in NVIDIA TX1 BootROM when Recovery Mode (RCM) is active. A physical attacker can bypass secure boot and execute unverified code with elevated privileges.


Affected software

Cisco WebEx Room Kit PLus
Cisco WebEx Room Kit
Cisco WebEx Room 70
Cisco WebEx Room 55

How to mitigate CVE-2018-6242

Update to version 9.2.6, 9.3.2.

Cisco WebEx Room Kit PLus - addressed in versions 9.2.6, 9.3.2
Cisco WebEx Room Kit - addressed in versions 9.2.6, 9.3.2
Cisco WebEx Room 70 - addressed in versions 9.2.6, 9.3.2
Cisco WebEx Room 55 - addressed in versions 9.2.6, 9.3.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins