Use of hard-coded credentials in Policy Suite - CVE-2018-0375

 

Use of hard-coded credentials in Policy Suite - CVE-2018-0375

Published: July 20, 2018 / Updated: July 23, 2018


Vulnerability identifier: #VU13948
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0375
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The vulnerability exists in the Cluster Manager of Cisco Policy Suite due to the presence of undocumented, static user credentials for the root account. A remote attacker can use the account to log in to the system execute arbitrary commands with root privileges.


Affected software

Policy Suite

How to mitigate CVE-2018-0375

Update to version 18.1.0, 18.2.0.

Policy Suite - addressed in versions 18.1.0, 18.2.0

External References

Related Security Bulletins