Authentication bypass in Policy Suite - CVE-2018-0374

 

Authentication bypass in Policy Suite - CVE-2018-0374

Published: July 20, 2018


Vulnerability identifier: #VU13947
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0374
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication on the target system.

The vulnerability exists in the Policy Builder database of Cisco Policy Suite due to lack of authentication. A remote attacker can bypass authentication, directly connect to the to the Policy Builder database  to access and change any data in the Policy Builder database.


Affected software

Policy Suite

How to mitigate CVE-2018-0374

Update to version 18.1.0.

Policy Suite - update to 18.1.0

External References

Related Security Bulletins