CVE-2018-0262
published 2018-05-02CVE-2018-0262: A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information…
PriorityP355high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
4.10%
89.6th percentile
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system, leading to Remote Code Execution. The vulnerability is due to incorrect default configuration of the device, which can expose internal interfaces and ports on the external interface of the system. A successful exploit could allow the attacker to gain unauthenticated access to configuration and database files as well as sensitive meeting information on an affected system. Additionally, if the Traversal Using Relay NAT (TURN) service is enabled and utilizing Transport Layer Security (TLS) connections, an attacker could utilize TURN credentials to forward traffic to device daemons, allowing for remote exploitation. This vulnerability affects Cisco Meeting Server (CMS) Acano X-series platforms that are running a CMS Software release prior to 2.2.11. Cisco Bug IDs: CSCvg76469.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Meeting Server Remote Code Execution Vulnerability
vendor_cisco·2018-05-02·CVSS 8.8
CVE-2018-0262 [HIGH] CWE-16 Cisco Meeting Server Remote Code Execution Vulnerability
Cisco Meeting Server Remote Code Execution Vulnerability
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system.
The vulnerability is due to incorrect default configuration of the device, which can expose internal interfaces and ports on the external interface of the system. A successful exploit could allow the attacker to gain unauthenticated access to configuration and database files as well as sensitive meeting information on an affected system.
Additionally, if the Traversal Using Relay NAT (TURN) service is enabled and utilizing Transport Layer Security (TLS) connections, an attacker could utilize TURN credentials to forward traffic to device daemons, allow
Cisco
Cisco Meeting Server Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0262 Cisco Meeting Server Remote Code Execution Vulnerability
CVE-2018-0262: Cisco Meeting Server Remote Code Execution Vulnerability
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system. The vulnerability is due to incorrect default configuration of the device, which can expose internal interfaces and ports on the external interface of the system. A successful exploit could allow the attacker to gain unauthenticated access to configuration and database files as well as sensitive meeting information on an affected system. Additionally, if the Traversal Using Relay NAT (TURN) service is enabled and utilizing Transport Layer Security (TLS) connections, an attacker could utilize TURN credentials to forward traffic to device da
GHSA
GHSA-jr24-4pv3-cjgv: A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive inf
ghsa_unreviewed·2022-05-13
CVE-2018-0262 [HIGH] GHSA-jr24-4pv3-cjgv: A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive inf
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system, leading to Remote Code Execution. The vulnerability is due to incorrect default configuration of the device, which can expose internal interfaces and ports on the external interface of the system. A successful exploit could allow the attacker to gain unauthenticated access to configuration and database files as well as sensitive meeting information on an affected system. Additionally, if the Traversal Using Relay NAT (TURN) service is enabled and utilizing Transport Layer Security (TLS) connections, an attacker could utilize TURN credentials to forward traffic to device daemons, allowing for remote exploitatio
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5098 Mozilla: Use-after-free while manipulating form input elements (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5098 [CRITICAL] CVE-2018-5098 Mozilla: Use-after-free while manipulating form input elements (MFSA 2018-03)
CVE-2018-5098 Mozilla: Use-after-free while manipulating form input elements (MFSA 2018-03)
A use-after-free vulnerability can occur when manipulating form input elements, focus, and selections through script. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5098
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 https://access.redhat.com/errata/RHSA-2018:
Bugzilla
CVE-2018-5104 Mozilla: Use-after-free during font face manipulation (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5104 [CRITICAL] CVE-2018-5104 Mozilla: Use-after-free during font face manipulation (MFSA 2018-03)
CVE-2018-5104 Mozilla: Use-after-free during font face manipulation (MFSA 2018-03)
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5104
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 https://access.redhat.com/errata/RHSA-2018:0262
Bugzilla
CVE-2018-5099 Mozilla: Use-after-free with widget listener (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5099 [CRITICAL] CVE-2018-5099 Mozilla: Use-after-free with widget listener (MFSA 2018-03)
CVE-2018-5099 Mozilla: Use-after-free with widget listener (MFSA 2018-03)
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5099
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 http
Bugzilla
CVE-2018-5103 Mozilla: Use-after-free during mouse event handling (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5103 [CRITICAL] CVE-2018-5103 Mozilla: Use-after-free during mouse event handling (MFSA 2018-03)
CVE-2018-5103 Mozilla: Use-after-free during mouse event handling (MFSA 2018-03)
A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5103
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 https://access.redhat.com/errata/RHSA-2018:0262
Bugzilla
CVE-2018-5096 Mozilla: Use-after-free while editing form elements (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5096 [CRITICAL] CVE-2018-5096 Mozilla: Use-after-free while editing form elements (MFSA 2018-03)
CVE-2018-5096 Mozilla: Use-after-free while editing form elements (MFSA 2018-03)
A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5096
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 https://access.redhat.com/errata/RHSA-2018:0262
Bugzilla
CVE-2018-5102 Mozilla: Use-after-free in HTML media elements (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5102 [CRITICAL] CVE-2018-5102 Mozilla: Use-after-free in HTML media elements (MFSA 2018-03)
CVE-2018-5102 Mozilla: Use-after-free in HTML media elements (MFSA 2018-03)
A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5102
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 https://access.redhat.com/errata/RHSA-2018:0262
http://www.securityfocus.com/bid/104079http://www.securitytracker.com/id/1040819https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180502-cms-cxhttp://www.securityfocus.com/bid/104079http://www.securitytracker.com/id/1040819https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180502-cms-cx
2018-05-02
Published