HIGH · 7.8

CVE-2018-0302

A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The v...

Vulnerability Description

A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to incorrect input validation in the CLI parser subsystem. An attacker could exploit this vulnerability by exceeding the expected length of user input. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the affected system. This vulnerability affects Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCvb61099, CSCvb86743.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoNx-Os3.1\(1k\)a
CiscoUcs 6120Xp-
CiscoUcs 6140Xp-
CiscoUcs 6248Up-
CiscoUcs 6296Up-
CiscoUcs 6324-
CiscoUcs 6332-
CiscoFirepower Extensible Operating System>= 1.1, < 1.1.4.169
CiscoFirepower 4110-
CiscoFirepower 4120-
CiscoFirepower 4140-
CiscoFirepower 4150-
CiscoFirepower 9300 Security Appliance-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-0302?

CVE-2018-0302 is a vulnerability with a CVSS score of 7.8 (HIGH). A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The v...

How severe is CVE-2018-0302?

CVE-2018-0302 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-0302?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Ucs 6120Xp, Cisco Ucs 6140Xp, Cisco Ucs 6248Up, Cisco Ucs 6296Up.