First published: Wed Jul 18 2018(Updated: )
A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to access the Policy Builder interface. The vulnerability is due to a lack of authentication. An attacker could exploit this vulnerability by accessing the Policy Builder interface. A successful exploit could allow the attacker to make changes to existing repositories and create new repositories. Cisco Bug IDs: CSCvi35109.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Mobility Services Engine 3310 | =18.0.0 | |
Cisco Policy Suite Software | <18.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0376 is considered a high severity vulnerability due to the potential for unauthenticated remote access.
To mitigate CVE-2018-0376, upgrade to Cisco Policy Suite version 18.2.0 or later.
CVE-2018-0376 affects Cisco Policy Suite versions prior to 18.2.0 and Cisco Mobility Services Engine version 18.0.0.
CVE-2018-0376 is an authentication vulnerability that allows remote attackers to access the Policy Builder interface without authentication.
Yes, CVE-2018-0376 can be exploited remotely by unauthenticated attackers.