CVE-2018-0376

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
18/07/2018
Last modified:
09/10/2019

Description

A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to access the Policy Builder interface. The vulnerability is due to a lack of authentication. An attacker could exploit this vulnerability by accessing the Policy Builder interface. A successful exploit could allow the attacker to make changes to existing repositories and create new repositories. Cisco Bug IDs: CSCvi35109.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:mobility_services_engine:18.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:policy_suite:*:*:*:*:*:*:*:* 18.2.0 (excluding)