cbcvebase.
CVE-2018-0279
published 2018-05-17

CVE-2018-0279: A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker…

PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
4.57%
90.6th percentile
A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation of command arguments. An attacker could exploit this vulnerability by using crafted arguments when opening a connection to the affected device. An exploit could allow the attacker to gain shell access with a non-root user account to the underlying Linux operating system on the affected device. Due to the system design, access to the Linux shell could allow execution of additional attacks that may have a significant impact on the affected system. This vulnerability affects Cisco devices that are running release 3.7.1, 3.6.3, or earlier releases of Cisco Enterprise NFV Infrastructure Software (NFVIS) when access to the SCP server is allowed on the affected device. Cisco NFVIS Releases 3.5.x and 3.6.x do allow access to the SCP server by default, while Cisco NFVIS Release 3.7.1 does not. Cisco Bug IDs: CSCvh25026.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoenterprise_nfv_infrastructure
ciscoenterprise_nfv_infrastructure_software< 3.6.33.6.3
ciscoenterprise_nfv_infrastructure_software

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for crafted SCP command arguments used when opening a connection to Cisco NFVIS devices, which may indicate exploitation attempts targeting the SCP server's improper input validation.
  • Alert on unexpected Linux shell access originating from SCP sessions on Cisco NFVIS devices, particularly from non-root user accounts, as this may indicate successful exploitation.
  • Focus detection on Cisco NFVIS releases 3.5.x and 3.6.x, which allow SCP server access by default and are therefore exposed to exploitation without additional configuration changes.
  • ·Cisco NFVIS Release 3.7.1 does NOT enable SCP server access by default, reducing exposure. Releases 3.5.x and 3.6.x DO enable SCP server access by default, making them inherently exposed unless explicitly disabled.
  • ·The vulnerability only affects devices where SCP server access is permitted. Disabling SCP server access reduces the attack surface, though Cisco states there are no workarounds that fully address the vulnerability.
  • ·There are no workarounds available for this vulnerability; software updates are the only remediation.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat6.8MEDIUM
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.