Vulnerability Description
A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by accessing the Policy Builder interface and modifying an HTTP request. A successful exploit could allow the attacker to make changes to existing policies. Cisco Bug IDs: CSCvi35007.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Mobility Services Engine 3365 Firmware | 18.0.0 |
| Cisco | Mobility Services Engine 3365 | - |
| Cisco | Mobility Services Engine 3355 Firmware | 18.0.0 |
| Cisco | Mobility Services Engine 3355 | - |
| Cisco | Mobility Services Engine 3310 Firmware | 18.0.0 |
| Cisco | Mobility Services Engine 3310 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/104867Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- http://www.securityfocus.com/bid/104867Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2018-0393?
CVE-2018-0393 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface....
How severe is CVE-2018-0393?
CVE-2018-0393 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-0393?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Mobility Services Engine 3365 Firmware, Cisco Mobility Services Engine 3365, Cisco Mobility Services Engine 3355 Firmware, Cisco Mobility Services Engine 3355, Cisco Mobility Services Engine 3310 Firmware.