Authentication bypass in Policy Suite - CVE-2018-0377

 

Authentication bypass in Policy Suite - CVE-2018-0377

Published: July 20, 2018


Vulnerability identifier: #VU13946
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0377
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication on the target system.

The vulnerability exists in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite due to lack of authentication. A remote attacker can bypass authentication, directly connect to the OSGi interface to access or change any files that are accessible by the OSGi process.


Affected software

Policy Suite

How to mitigate CVE-2018-0377

Update to version 18.1.0.

Policy Suite - update to 18.1.0

External References

Related Security Bulletins