CVE-2018-0290Cisco Socialminer vulnerability

CWE-3994 documents4 sources
Severity
5.3MEDIUMNVD
EPSS
0.5%
top 35.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateMay 13

Description

A vulnerability in the TCP stack of Cisco SocialMiner could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the notification system. The vulnerability is due to faulty handling of new TCP connections to the affected application. An attacker could exploit this vulnerability by sending a malicious TCP packet to the vulnerable service. An exploit could allow the attacker to create a DoS condition by interrupting certain phone services. A manual restart of t

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

NVDcisco/socialminer11.6\(1\)

🔴Vulnerability Details

2
GHSA
GHSA-8f5c-4jx4-7pq4: A vulnerability in the TCP stack of Cisco SocialMiner could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in2022-05-13
CVEList
CVE-2018-0290: A vulnerability in the TCP stack of Cisco SocialMiner could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in2018-05-17

📋Vendor Advisories

1
Cisco
Cisco SocialMiner Notification System Denial of Service Vulnerability2018-05-16
CVE-2018-0290 — Cisco Socialminer vulnerability | cvebase