CVE-2018-0352

Severity
6.7MEDIUM
EPSS
0.1%
top 82.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateMay 13

Description

A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to elevate their privilege level to root. The attacker must have valid user credentials with super user privileges (level 15) to log in to the device. The vulnerability is due to insufficient validation of script files executed in the context of the Disk Check Tool. An attacker could exploit this vulnerability by replacing one script file wi

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5cisco_wide_area_application_services_unknownCisco Wide Area Application Services unknown

🔴Vulnerability Details

2
GHSA
GHSA-wqg8-f34c-vm4v: A vulnerability in the Disk Check Tool (disk-check2022-05-13
CVEList
CVE-2018-0352: A vulnerability in the Disk Check Tool (disk-check2018-06-07

📋Vendor Advisories

1
Cisco
Cisco Wide Area Application Services Software Scripts Privilege Escalation Vulnerability2018-06-06
CVE-2018-0352 (MEDIUM CVSS 6.7) | A vulnerability in the Disk Check T | cvebase.io