Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-0302


A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to incorrect input validation in the CLI parser subsystem. An attacker could exploit this vulnerability by exceeding the expected length of user input. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the affected system. This vulnerability affects Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCvb61099, CSCvb86743.


Published

2018-06-21T11:29:00.367

Last Modified

2024-11-21T03:37:56.007

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco nx-os 3.1\(1k\)a Yes
Hardware cisco ucs_6120xp - No
Hardware cisco ucs_6140xp - No
Hardware cisco ucs_6248up - No
Hardware cisco ucs_6296up - No
Hardware cisco ucs_6324 - No
Hardware cisco ucs_6332 - No
Operating System cisco firepower_extensible_operating_system < 1.1.4.169 Yes
Operating System cisco firepower_extensible_operating_system < 2.0.1.135 Yes
Hardware cisco firepower_4110 - No
Hardware cisco firepower_4120 - No
Hardware cisco firepower_4140 - No
Hardware cisco firepower_4150 - No
Operating System cisco firepower_extensible_operating_system < 1.1.4.169 Yes
Operating System cisco firepower_extensible_operating_system < 2.0.1.135 Yes
Hardware cisco firepower_9300_security_appliance - No

References