CVE-2018-0149

Severity
4.8MEDIUM
EPSS
0.2%
top 51.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateMay 13

Description

A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected softwa

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

CVEListV5cisco_integrated_management_controller_supervisor_and_cisco_ucs_director_unknownCisco Integrated Management Controller Supervisor and Cisco UCS Director unknown

🔴Vulnerability Details

2
GHSA
GHSA-qwmw-8xh3-c9fx: A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software co2022-05-13
CVEList
CVE-2018-0149: A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software co2018-06-07

📋Vendor Advisories

1
Cisco
Cisco Integrated Management Controller Supervisor and Cisco UCS Director DOM Stored Cross-Site Scripting Vulnerability2018-06-06
CVE-2018-0149 (MEDIUM CVSS 4.8) | A vulnerability in the web-based ma | cvebase.io