ID

VAR-201810-0333


CVE

CVE-2018-0459


TITLE

Cisco Enterprise NFV Infrastructure Software Authorization vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-011267

DESCRIPTION

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerability is due to insufficient server-side authorization checks. An attacker who is logged in to the web-based management interface as a low-privileged user could exploit this vulnerability by sending a crafted HTTP request. A successful exploit could allow the attacker to use the low-privileged user account to reboot or shut down the affected system. Cisco Enterprise NFV Infrastructure Software (NFVIS) Contains an authorization vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Attackers can exploit this issue to cause denial-of-service condition, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCvj07789. The platform can realize the full lifecycle management of virtualized services through the central coordinator and controller

Trust: 1.98

sources: NVD: CVE-2018-0459 // JVNDB: JVNDB-2018-011267 // BID: 105290 // VULHUB: VHN-118661

AFFECTED PRODUCTS

vendor:ciscomodel:network functions virtualization infrastructurescope:eqversion: -

Trust: 1.6

vendor:ciscomodel:enterprise nfv infrastructure softwarescope: - version: -

Trust: 0.8

vendor:ciscomodel:enterprise nfv infrastructure softwarescope:eqversion:0

Trust: 0.3

sources: BID: 105290 // JVNDB: JVNDB-2018-011267 // CNNVD: CNNVD-201809-278 // NVD: CVE-2018-0459

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-0459
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-0459
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201809-278
value: MEDIUM

Trust: 0.6

VULHUB: VHN-118661
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-0459
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-118661
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-0459
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-118661 // JVNDB: JVNDB-2018-011267 // CNNVD: CNNVD-201809-278 // NVD: CVE-2018-0459

PROBLEMTYPE DATA

problemtype:CWE-285

Trust: 1.9

problemtype:CWE-863

Trust: 1.1

sources: VULHUB: VHN-118661 // JVNDB: JVNDB-2018-011267 // NVD: CVE-2018-0459

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201809-278

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201809-278

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-011267

PATCH

title:cisco-sa-20180905-nfvis-dosurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-nfvis-dos

Trust: 0.8

title:Cisco Enterprise NFV Infrastructure Software Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=84609

Trust: 0.6

sources: JVNDB: JVNDB-2018-011267 // CNNVD: CNNVD-201809-278

EXTERNAL IDS

db:NVDid:CVE-2018-0459

Trust: 2.8

db:BIDid:105290

Trust: 2.0

db:JVNDBid:JVNDB-2018-011267

Trust: 0.8

db:CNNVDid:CNNVD-201809-278

Trust: 0.7

db:VULHUBid:VHN-118661

Trust: 0.1

sources: VULHUB: VHN-118661 // BID: 105290 // JVNDB: JVNDB-2018-011267 // CNNVD: CNNVD-201809-278 // NVD: CVE-2018-0459

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20180905-nfvis-dos

Trust: 2.0

url:http://www.securityfocus.com/bid/105290

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-0459

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-0459

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-118661 // BID: 105290 // JVNDB: JVNDB-2018-011267 // CNNVD: CNNVD-201809-278 // NVD: CVE-2018-0459

CREDITS

Security Teams of Orange Group

Trust: 0.3

sources: BID: 105290

SOURCES

db:VULHUBid:VHN-118661
db:BIDid:105290
db:JVNDBid:JVNDB-2018-011267
db:CNNVDid:CNNVD-201809-278
db:NVDid:CVE-2018-0459

LAST UPDATE DATE

2024-08-14T14:45:36.931000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-118661date:2019-10-09T00:00:00
db:BIDid:105290date:2018-09-05T00:00:00
db:JVNDBid:JVNDB-2018-011267date:2019-01-09T00:00:00
db:CNNVDid:CNNVD-201809-278date:2019-10-17T00:00:00
db:NVDid:CVE-2018-0459date:2019-10-09T23:32:07.943

SOURCES RELEASE DATE

db:VULHUBid:VHN-118661date:2018-10-05T00:00:00
db:BIDid:105290date:2018-09-05T00:00:00
db:JVNDBid:JVNDB-2018-011267date:2019-01-09T00:00:00
db:CNNVDid:CNNVD-201809-278date:2018-09-06T00:00:00
db:NVDid:CVE-2018-0459date:2018-10-05T14:29:03.920