V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-15439
CVE
Critical

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentica…

CVSS
9.8
Critical
EPSS
0.50
p97
Published
2018-01-01
Updated
2018-01-01
Description

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. An attacker could exploit this vulnerability by using this account to log in to an affected device and execute commands with full admin rights. Cisco has not released software updates that address this vulnerability. This advisory will be updated with fixed software information once fixed software becomes available. There is a workaround to address this vulnerability.

Tags · CWE
Pre-auth
CWE-798
CAPEC-70
CAPEC-191
Affected products
Sf200-24_firmwareSf200-24fp_firmwareSf200-24p_firmwareSf200-48_firmwareSf200-48p_firmwareSf250-24_firmwareSf250-24p_firmwareSf250-48_firmwareSf250-48hp_firmwareSf300-08_firmwareSf300-24_firmwareSf300-24mp_firmwareSf300-24p_firmwareSf300-24pp_firmwareSf300-48_firmwareSf300-48p_firmwareSf300-48pp_firmwareSf302-08_firmwareSf302-08mp_firmwareSf302-08mpp_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.496 · p97
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-70 · CWE-798
└ via CAPEC-191 · CWE-798
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
sf200-24_firmware*Tracked
sf200-24fp_firmware*Tracked
sf200-24p_firmware*Tracked
sf200-48_firmware*Tracked
sf200-48p_firmware*Tracked
sf250-24_firmware*Tracked
sf250-24p_firmware*Tracked
sf250-48_firmware*Tracked
sf250-48hp_firmware*Tracked
sf300-08_firmware*Tracked
sf300-24_firmware*Tracked
sf300-24mp_firmware*Tracked
sf300-24p_firmware*Tracked
sf300-24pp_firmware*Tracked
sf300-48_firmware*Tracked
sf300-48p_firmware*Tracked
sf300-48pp_firmware*Tracked
sf302-08_firmware*Tracked
sf302-08mp_firmware*Tracked
sf302-08mpp_firmware*Tracked
Source databases
CVE
Related vulnerabilities