Vulnerability Description
A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to incorrect input validation in the CLI parser subsystem. An attacker could exploit this vulnerability by exceeding the expected length of user input. A successful exploit could allow the attacker to execute arbitrary code with root privileges on the affected system. This vulnerability affects Firepower 4100 Series Next-Generation Firewall, Firepower 9300 Security Appliance, UCS 6100 Series Fabric Interconnects, UCS 6200 Series Fabric Interconnects, UCS 6300 Series Fabric Interconnects. Cisco Bug IDs: CSCvb61099, CSCvb86743.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | 3.1\(1k\)a |
| Cisco | Ucs 6120Xp | - |
| Cisco | Ucs 6140Xp | - |
| Cisco | Ucs 6248Up | - |
| Cisco | Ucs 6296Up | - |
| Cisco | Ucs 6324 | - |
| Cisco | Ucs 6332 | - |
| Cisco | Firepower Extensible Operating System | >= 1.1, < 1.1.4.169 |
| Cisco | Firepower 4110 | - |
| Cisco | Firepower 4120 | - |
| Cisco | Firepower 4140 | - |
| Cisco | Firepower 4150 | - |
| Cisco | Firepower 9300 Security Appliance | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2018-0302?
CVE-2018-0302 is a vulnerability with a CVSS score of 7.8 (HIGH). A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The v...
How severe is CVE-2018-0302?
CVE-2018-0302 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-0302?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Nx-Os, Cisco Ucs 6120Xp, Cisco Ucs 6140Xp, Cisco Ucs 6248Up, Cisco Ucs 6296Up.