CVE-2018-0279
published 2018-05-17CVE-2018-0279: A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
4.57%
90.6th percentile
A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation of command arguments. An attacker could exploit this vulnerability by using crafted arguments when opening a connection to the affected device. An exploit could allow the attacker to gain shell access with a non-root user account to the underlying Linux operating system on the affected device. Due to the system design, access to the Linux shell could allow execution of additional attacks that may have a significant impact on the affected system. This vulnerability affects Cisco devices that are running release 3.7.1, 3.6.3, or earlier releases of Cisco Enterprise NFV Infrastructure Software (NFVIS) when access to the SCP server is allowed on the affected device. Cisco NFVIS Releases 3.5.x and 3.6.x do allow access to the SCP server by default, while Cisco NFVIS Release 3.7.1 does not. Cisco Bug IDs: CSCvh25026.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | enterprise_nfv_infrastructure | — | — |
| cisco | enterprise_nfv_infrastructure_software | < 3.6.3 | 3.6.3 |
| cisco | enterprise_nfv_infrastructure_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for crafted SCP command arguments used when opening a connection to Cisco NFVIS devices, which may indicate exploitation attempts targeting the SCP server's improper input validation. ↗
- →Alert on unexpected Linux shell access originating from SCP sessions on Cisco NFVIS devices, particularly from non-root user accounts, as this may indicate successful exploitation. ↗
- →Focus detection on Cisco NFVIS releases 3.5.x and 3.6.x, which allow SCP server access by default and are therefore exposed to exploitation without additional configuration changes. ↗
- ·Cisco NFVIS Release 3.7.1 does NOT enable SCP server access by default, reducing exposure. Releases 3.5.x and 3.6.x DO enable SCP server access by default, making them inherently exposed unless explicitly disabled. ↗
- ·The vulnerability only affects devices where SCP server access is permitted. Disabling SCP server access reduces the attack surface, though Cisco states there are no workarounds that fully address the vulnerability. ↗
- ·There are no workarounds available for this vulnerability; software updates are the only remediation. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat6.8MEDIUM
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
vendor_redhat·2018-05-30·CVSS 6.8
CVE-2018-12532 [MEDIUM] CWE-94 RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.
Statement: This issue does not affect the following Red Hat products, as they do not include the vulnerable version of the RichFaces component:
Red Hat JBoss EAP 5.2
Red Hat JBoss Data Virtualization 6.4
Red Hat JBoss BRMS 5.3
Red Hat JBoss Operations Network 3.3
Package: RichFaces (JBoss Developer Studio 11) - Not affected
Package: RichFaces (Red Hat JBoss BRMS 5) - Not affected
Package: RichFaces (Red Hat JBoss Data Virtuali
Cisco
Cisco Enterprise NFV Infrastructure Software Linux Shell Access Vulnerability
vendor_cisco·2018-05-16·CVSS 6.3
CVE-2018-0279 [MEDIUM] CWE-20 Cisco Enterprise NFV Infrastructure Software Linux Shell Access Vulnerability
Cisco Enterprise NFV Infrastructure Software Linux Shell Access Vulnerability
A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device.
The vulnerability is due to improper input validation of command arguments. An attacker could exploit this vulnerability by using crafted arguments when opening a connection to the affected device. An exploit could allow the attacker to gain shell access with a non-root user account to the underlying Linux operating system on the affected device.
Due to the system design, access to the Linux shell could allow execution of additional attacks that may have a significant imp
Cisco
Cisco Enterprise NFV Infrastructure Software Linux Shell Access Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0279 Cisco Enterprise NFV Infrastructure Software Linux Shell Access Vulnerability
CVE-2018-0279: Cisco Enterprise NFV Infrastructure Software Linux Shell Access Vulnerability
A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation of command arguments. An attacker could exploit this vulnerability by using crafted arguments when opening a connection to the affected device. An exploit could allow the attacker to gain shell access with a non- root user account to the underlying Linux operating system on the affected device. Due to the system design, access to the Linux shell could allow execution of additional attacks that may have a s
GHSA
GHSA-2534-25mr-h93h: A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote
ghsa_unreviewed·2022-05-13
CVE-2018-0279 [HIGH] CWE-78 GHSA-2534-25mr-h93h: A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote
A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation of command arguments. An attacker could exploit this vulnerability by using crafted arguments when opening a connection to the affected device. An exploit could allow the attacker to gain shell access with a non-root user account to the underlying Linux operating system on the affected device. Due to the system design, access to the Linux shell could allow execution of additional attacks that may have a significant impact on the affected system. This vulnerability affects Cisco devices that are ru
No detection rules found.
No public exploits indexed.
2018-05-17
Published