HIGH · 8.8

CVE-2018-0365

A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and per...

Vulnerability Description

A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions on the targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCvb19750.

CVSS Score

8.8

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoSecure Firewall Management Center6.0.1
CiscoFirepower Appliance 8360 Firmware6.0.1
CiscoFirepower Appliance 8360All versions
CiscoFirepower Management Center 2500 Firmware6.0.1
CiscoFirepower Management Center 2500All versions
CiscoFirepower Appliance 8120 Firmware6.0.1
CiscoFirepower Appliance 8120All versions
CiscoFirepower Appliance 8260 Firmware6.0.1
CiscoFirepower Appliance 8260All versions
CiscoFirepower Appliance 7050 Firmware6.0.1
CiscoFirepower Appliance 7050All versions
CiscoFirepower Appliance 8130 Firmware6.0.1
CiscoFirepower Appliance 8130All versions
CiscoFirepower Appliance 8140 Firmware6.0.1
CiscoFirepower Appliance 8140All versions
CiscoFirepower Appliance 8350 Firmware6.0.1
CiscoFirepower Appliance 8350All versions
CiscoAmp 8150 Firmware6.0.1
CiscoAmp 8150All versions
CiscoAmp 7150 Firmware6.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-0365?

CVE-2018-0365 is a vulnerability with a CVSS score of 8.8 (HIGH). A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and per...

How severe is CVE-2018-0365?

CVE-2018-0365 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-0365?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Secure Firewall Management Center, Cisco Firepower Appliance 8360 Firmware, Cisco Firepower Appliance 8360, Cisco Firepower Management Center 2500 Firmware, Cisco Firepower Management Center 2500.