CVE-2018-0463
Severity
7.5HIGH
EPSS
0.6%
top 29.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 5
Latest updateMay 13
Description
A vulnerability in the Cisco Network Plug and Play server component of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to gain unauthorized access to configuration data that is stored on an affected NSO system. The vulnerability exists because the Network Plug and Play component performs incomplete validation when configured to use secure unique device identifiers (SUDI) for authentication. An attacker who controls a Cisco device that supports SUDI authe…
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-q65f-gxh5-gqxg: A vulnerability in the Cisco Network Plug and Play server component of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remot↗2022-05-13
CVEList▶
Cisco Network Services Orchestrator Network Plug and Play Information Disclosure Vulnerability↗2018-10-05
📋Vendor Advisories
1Cisco▶
Cisco Network Services Orchestrator Network Plug and Play Information Disclosure Vulnerability↗2018-09-05