CVE-2018-0095
published 2018-01-18CVE-2018-0095: A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could…
PriorityP342high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.40%
32.3th percentile
A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a privilege level of a guest user. The vulnerability is due to an incorrect networking configuration at the administrative shell CLI. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a set of crafted, malicious commands at the administrative shell. An exploit could allow the attacker to gain root access on the device. Cisco Bug IDs: CSCvb34303, CSCvb35726.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | email_security_and_content_security_management_appliance | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Email Security and Content Security Management Appliance Privilege Escalation Vulnerability
vendor_cisco·2018-01-18·CVSS 7.8
CVE-2018-0095 [HIGH] CWE-264 Cisco Email Security and Content Security Management Appliance Privilege Escalation Vulnerability
Cisco Email Security and Content Security Management Appliance Privilege Escalation Vulnerability
A vulnerability in the administrative shell of the Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a privilege level of a guest user.
The vulnerability is due to an incorrect networking configuration at the administrative shell CLI. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a set of crafted, malicious commands at the administrative shell. An exploit could allow the attacker to gain root access on the device.
Cisco has released software up
Cisco
Cisco Email Security and Content Security Management Appliance Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0095 Cisco Email Security and Content Security Management Appliance Privilege Escalation Vulnerability
CVE-2018-0095: Cisco Email Security and Content Security Management Appliance Privilege Escalation Vulnerability
A vulnerability in the administrative shell of the Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a privilege level of a guest user. The vulnerability is due to an incorrect networking configuration at the administrative shell CLI. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a set of crafted, malicious commands at the administrative shell. An exploit could allow the attacker to gain root access on the device. Cisco has released
GHSA
GHSA-24rf-59x9-98x7: A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) c
ghsa_unreviewed·2022-05-13
CVE-2018-0095 [HIGH] GHSA-24rf-59x9-98x7: A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) c
A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a privilege level of a guest user. The vulnerability is due to an incorrect networking configuration at the administrative shell CLI. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a set of crafted, malicious commands at the administrative shell. An exploit could allow the attacker to gain root access on the device. Cisco Bug IDs: CSCvb34303, CSCvb35726.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-2629 OpenJDK: GSS context use-after-free (JGSS, 8186212)
bugzilla·2018-01-15·CVSS 5.3
CVE-2018-2629 [MEDIUM] CVE-2018-2629 OpenJDK: GSS context use-after-free (JGSS, 8186212)
CVE-2018-2629 OpenJDK: GSS context use-after-free (JGSS, 8186212)
It was discovered that the JGSS component of OpenJDK failed to properly handle GSS context in the native GSS library wrapper in certain cases. A remote attacker could possibly make a Java application using JGSS to use previously freed context.
Discussion:
Public now via Oracle CPU January 2018:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html#AppendixJAVA
The issue was fixed in Oracle JDK 9.0.4, 8u161, 7u171, and 6u181.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0095 https://access.redhat.com/errata/RHSA-2018:0095
---
This issue has been addressed in the following products:
Oracle Java for Red Hat Ente
Bugzilla
CVE-2018-2582 OpenJDK: insufficient validation of the invokeinterface instruction (Hotspot, 8174962)
bugzilla·2018-01-15·CVSS 6.5
CVE-2018-2582 [MEDIUM] CVE-2018-2582 OpenJDK: insufficient validation of the invokeinterface instruction (Hotspot, 8174962)
CVE-2018-2582 OpenJDK: insufficient validation of the invokeinterface instruction (Hotspot, 8174962)
It was discovered that the Hotspot component of OpenJDK failed to properly validate uses of the invokeinterface Java Virtual Machine instruction. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Discussion:
Public now via Oracle CPU January 2018:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html#AppendixJAVA
The issue was fixed in Oracle JDK 9.0.4 and 8u161.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0095 https://access.redhat.com/errata/RHSA-2018:0095
---
This issue has been addressed in the following products:
O
Bugzilla
CVE-2018-2602 OpenJDK: loading of classes from untrusted locations (I18n, 8182601)
bugzilla·2018-01-15·CVSS 4.5
CVE-2018-2602 [MEDIUM] CVE-2018-2602 OpenJDK: loading of classes from untrusted locations (I18n, 8182601)
CVE-2018-2602 OpenJDK: loading of classes from untrusted locations (I18n, 8182601)
It was discovered that the I18n component of OpenJDK could use an untrusted search path when loading resource bundle classes. A local attacker could possibly use this flaw to execute arbitrary code as another local user by making their Java application load an attacker controlled class file.
Discussion:
Public now via Oracle CPU January 2018:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html#AppendixJAVA
The issue was fixed in Oracle JDK 9.0.4, 8u161, 7u171, and 6u181.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0095 https://access.redhat.com/errata/RHSA-2018:0095
---
This issue has been
http://www.securityfocus.com/bid/102729http://www.securitytracker.com/id/1040221http://www.securitytracker.com/id/1040222https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180117-esasmahttp://www.securityfocus.com/bid/102729http://www.securitytracker.com/id/1040221http://www.securitytracker.com/id/1040222https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180117-esasma
2018-01-18
Published