#VU13946 Authentication bypass in Policy Suite - CVE-2018-0377

 

#VU13946 Authentication bypass in Policy Suite - CVE-2018-0377

Published: July 20, 2018


Vulnerability identifier: #VU13946
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-0377
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Policy Suite
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to bypass authentication on the target system.

The vulnerability exists in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite due to lack of authentication. A remote attacker can bypass authentication, directly connect to the OSGi interface to access or change any files that are accessible by the OSGi process.


Remediation

Update to version 18.1.0.

External links