CVE-2018-0149
Severity
4.8MEDIUM
EPSS
0.2%
top 51.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 7
Latest updateMay 13
Description
A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected softwa…
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7
Affected Packages2 packages
▶CVEListV5cisco_integrated_management_controller_supervisor_and_cisco_ucs_director_unknownCisco Integrated Management Controller Supervisor and Cisco UCS Director unknown
🔴Vulnerability Details
2GHSA▶
GHSA-qwmw-8xh3-c9fx: A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software co↗2022-05-13
CVEList▶
CVE-2018-0149: A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software co↗2018-06-07
📋Vendor Advisories
1Cisco▶
Cisco Integrated Management Controller Supervisor and Cisco UCS Director DOM Stored Cross-Site Scripting Vulnerability↗2018-06-06