CVE-2018-0088
A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cisco IOS Software could allow an authenticated, local attacker to impact the stability of the device. This could result in arbitrary code execution or a denial of service (DoS) condition. The attacker has to have valid user credentials at privilege level 15. The vulnerability is due to a diagnostic test CLI command that allows the attacker to write to the device memory. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a specific diagnostic test command at the CLI. An exploit could allow the attacker to overwrite system memory locations, which could have a negative impact on the stability of the device. Cisco Bug IDs: CSCvf71150.
EPSS 0.39% · 31.0th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | industrial_ethernet_4010_series_firmware | |
| n/a | Cisco IOS | * |
Timeline
- Jan 18, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 28, 2021 EPSS Score
- Dec 30, 2021 EPSS Score
- Mar 3, 2022 EPSS Score
- May 5, 2022 EPSS Score
- Jul 8, 2022 EPSS Score
- Sep 10, 2022 EPSS Score
- Nov 12, 2022 EPSS Score
- Jan 14, 2023 EPSS Score