VDB
CVE-2018-0338
CVE-2018-0338
PUBLISHED
CVSS 4.599999904632568 MEDIUM
A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software lacks proper input and validation checks for certain file systems. An attacker could exploit this vulnerability by issuing crafted commands in the CLI of an affected system. A successful exploit could allow the attacker to cause other users to execute unwanted arbitrary commands on the affected system. Cisco Bug IDs: CSCvf52994.
EPSS 0.10% · 26.8th percentile
Risk Scores
CVSS 2.0
4.599999904632568
EPSS Score
0.10%
26.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | unified_computing_system | 5.5\(203\), 7.0\(0\)bz\(0.46\), 9.1\(1.13\) |
| n/a | Cisco Unified Computing System unknown | Cisco Unified Computing System unknown |
Exploit Intelligence
Timeline
- Jun 6, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score