#VU13947 Authentication bypass in Policy Suite - CVE-2018-0374

 

#VU13947 Authentication bypass in Policy Suite - CVE-2018-0374

Published: July 20, 2018


Vulnerability identifier: #VU13947
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-0374
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Policy Suite
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to bypass authentication on the target system.

The vulnerability exists in the Policy Builder database of Cisco Policy Suite due to lack of authentication. A remote attacker can bypass authentication, directly connect to the to the Policy Builder database  to access and change any data in the Policy Builder database.


Remediation

Update to version 18.1.0.

External links