CVE-2018-0088: High severity cisco industrial ethernet 4010 series firmware vulnerability
A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cisco IOS Software could allow an authenticated, local attacker to impact the stability of the device. This could result in arbitrary code execution or a denial of service (DoS) condition. The attacker has to have valid user credentials at privilege level 15. The vulnerability is due to a diagnostic test CLI command that allows the attacker to write to the device memory. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a specific diagnostic test command at the CLI. An exploit could allow the attacker to overwrite system memory locations, which could have a negative impact on the stability of the device. Cisco Bug IDs: CSCvf71150.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0088?
CVE-2018-0088 has a severity rating that indicates potential for stability impacts and possible arbitrary code execution.
How do I fix CVE-2018-0088?
To mitigate CVE-2018-0088, update to the latest version of the affected Cisco Industrial Ethernet 4010 Series Firmware.
Who is affected by CVE-2018-0088?
CVE-2018-0088 affects devices running vulnerable versions of Cisco IOS Software on Cisco Industrial Ethernet 4010 Series Switches.
What can an attacker do with CVE-2018-0088?
An authenticated, local attacker could exploit CVE-2018-0088 to cause denial of service or arbitrary code execution.
Is CVE-2018-0088 easy to exploit?
Exploitation of CVE-2018-0088 requires local access and authentication to the affected device, which may limit its attack surface.