CVE-2018-0428Improper Access Control in Systems INC WEB Security Appliance

Severity
6.7MEDIUMNVD
EPSS
0.1%
top 82.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15
Latest updateMay 13

Description

A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. The vulnerability is due to improper implementation of access controls. An attacker could exploit this vulnerability by authenticating to the device as a specific user to gain the information needed to elevate privileges to root in a separate login shell. A success

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-pc4c-2gp7-ch65: A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate priv2022-05-13
CVEList
CVE-2018-0428: A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate priv2018-08-15

📋Vendor Advisories

1
Cisco
Cisco Web Security Appliance Privilege Escalation Vulnerability2018-08-15
CVE-2018-0428 — Improper Access Control | cvebase