CVE-2018-0113

Severity
8.8HIGH
EPSS
1.1%
top 21.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 8
Latest updateMay 13

Description

A vulnerability in an operations script of Cisco UCS Central could allow an authenticated, remote attacker to execute arbitrary shell commands with the privileges of the daemon user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by posting a crafted request to the user interface of Cisco UCS Central. This vulnerability affects Cisco UCS Central Software prior to Release 2.0(1c). Cisco Bug IDs: CSCve70825.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5cisco_ucs_centralCisco UCS Central

🔴Vulnerability Details

2
GHSA
GHSA-4vp2-8c9h-5h96: A vulnerability in an operations script of Cisco UCS Central could allow an authenticated, remote attacker to execute arbitrary shell commands with th2022-05-13
CVEList
CVE-2018-0113: A vulnerability in an operations script of Cisco UCS Central could allow an authenticated, remote attacker to execute arbitrary shell commands with th2018-02-08

📋Vendor Advisories

1
Cisco
Cisco UCS Central Arbitrary Command Execution Vulnerability2018-02-08
CVE-2018-0113 (HIGH CVSS 8.8) | A vulnerability in an operations sc | cvebase.io