CVE-2018-0255
published 2018-04-19CVE-2018-0255: A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a…
PriorityP349high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.94%
57.2th percentile
A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to insufficient CSRF protection by the device manager web interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link or visit an attacker-controlled website. A successful exploit could allow the attacker to submit arbitrary requests to an affected device via the device manager web interface with the privileges of the user. This vulnerability affects the following Cisco Industrial Ethernet (IE) Switches if they are running a vulnerable release of Cisco IOS Software: IE 2000 Series, IE 2000U Series, IE 3000 Series, IE 3010 Series, IE 4000 Series, IE 4010 Series, IE 5000 Series. Cisco Bug IDs: CSCvc96405.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | industrial_ethernet_switches_device_manager | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Industrial Ethernet Switches Device Manager Cross-Site Request Forgery Vulnerability
vendor_cisco·2018-04-18·CVSS 8.8
CVE-2018-0255 [HIGH] CWE-352 Cisco Industrial Ethernet Switches Device Manager Cross-Site Request Forgery Vulnerability
Cisco Industrial Ethernet Switches Device Manager Cross-Site Request Forgery Vulnerability
A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system.
The vulnerability is due to insufficient CSRF protection by the device manager web interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link or visit an attacker-controlled website. A successful exploit could allow the attacker to submit arbitrary requests to an affected device via the device manager web interface with the privileges of the user.
There are no workarounds that address this vulnerability.
This
Cisco
Cisco Industrial Ethernet Switches Device Manager Cross-Site Request Forgery Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0255 Cisco Industrial Ethernet Switches Device Manager Cross-Site Request Forgery Vulnerability
CVE-2018-0255: Cisco Industrial Ethernet Switches Device Manager Cross-Site Request Forgery Vulnerability
A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to insufficient CSRF protection by the device manager web interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link or visit an attacker-controlled website. A successful exploit could allow the attacker to submit arbitrary requests to an affected device via the device manager web interface with the privileges of the user. There are no
CVSS: 3.0
CWE: CWE-352, CWE-352
Bug IDs
GHSA
GHSA-hgmm-mqqv-gqvx: A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a
ghsa_unreviewed·2022-05-13
CVE-2018-0255 [HIGH] CWE-352 GHSA-hgmm-mqqv-gqvx: A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a
A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to insufficient CSRF protection by the device manager web interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link or visit an attacker-controlled website. A successful exploit could allow the attacker to submit arbitrary requests to an affected device via the device manager web interface with the privileges of the user. This vulnerability affects the following Cisco Industrial Ethernet (IE) Switches if they are running a vulnerable release of Cisco IOS Software: IE 2000 Serie
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-04-19
Published