CVE-2018-0338
HIGHCisco Unified Computing System - Authenticated Command Injection via CLI
Title source: llmDescription
A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software lacks proper input and validation checks for certain file systems. An attacker could exploit this vulnerability by issuing crafted commands in the CLI of an affected system. A successful exploit could allow the attacker to cause other users to execute unwanted arbitrary commands on the affected system. Cisco Bug IDs: CSCvf52994.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1041071
Vendor Advisory x_refsource_confirm
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-ucs-access
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/104456
Scores
CVSS v3
7.8
EPSS
0.0038
EPSS Percentile
29.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
CWE-863
Status
published
Products (5)
cisco/unified_computing_system
5.5\(203\)
cisco/unified_computing_system
7.0\(0\)bz\(0.46\)
cisco/unified_computing_system
9.0\(100.20\)b
cisco/unified_computing_system
9.1\(1.13\)
cisco/unified_computing_system
9.9\(0.902\)
Published
Jun 07, 2018
Tracked Since
Feb 18, 2026