MEDIUM · 6.5

CVE-2018-0393

A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface....

Vulnerability Description

A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by accessing the Policy Builder interface and modifying an HTTP request. A successful exploit could allow the attacker to make changes to existing policies. Cisco Bug IDs: CSCvi35007.

CVSS Score

6.5

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
CiscoMobility Services Engine 3365 Firmware18.0.0
CiscoMobility Services Engine 3365-
CiscoMobility Services Engine 3355 Firmware18.0.0
CiscoMobility Services Engine 3355-
CiscoMobility Services Engine 3310 Firmware18.0.0
CiscoMobility Services Engine 3310-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-0393?

CVE-2018-0393 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface....

How severe is CVE-2018-0393?

CVE-2018-0393 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-0393?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Mobility Services Engine 3365 Firmware, Cisco Mobility Services Engine 3365, Cisco Mobility Services Engine 3355 Firmware, Cisco Mobility Services Engine 3355, Cisco Mobility Services Engine 3310 Firmware.