CVE-2018-0186
Last modified
CVE-2018-0186 is a vulnerability of currently unknown severity. Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software. The vulnerabilities are due to insufficient input validation of certain parameters that are passed to the affected software via the web UI. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software. The vulnerabilities are due to insufficient input validation of certain parameters that are passed to the affected software via the web UI. An attacker could exploit these vulnerabilities by persuading a user of the affected UI to access a malicious link or by intercepting a user request for the affected UI and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected UI or allow the attacker to access sensitive browser-based information on the user's system. Cisco Bug IDs: CSCuz38591, CSCvb09530, CSCvb10022.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | < 16.3.6 |
References
- http://www.securityfocus.com/bid/103551Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/103551Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-0186?
How severe is CVE-2018-0186?
How do I fix CVE-2018-0186?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-0180Multiple vulnerabilities in the Login Enhancements (Login Bl…5.9
- CVE-2018-0181A vulnerability in the Redis implementation used by the Cisc…7.3
- CVE-2018-0182Multiple vulnerabilities in the CLI parser of Cisco IOS XE S…
- CVE-2018-0183A vulnerability in the CLI parser of Cisco IOS XE Software c…
- CVE-2018-0184A vulnerability in the CLI parser of Cisco IOS XE Software c…
- CVE-2018-0185Multiple vulnerabilities in the CLI parser of Cisco IOS XE S…
- CVE-2018-0187A vulnerability in the Admin portal of Cisco Identity Servic…6.5
- CVE-2018-0188Multiple vulnerabilities in the web-based user interface (we…
- CVE-2018-0189A vulnerability in the Forwarding Information Base (FIB) cod…
- CVE-2018-0190Multiple vulnerabilities in the web-based user interface (we…
- CVE-2018-0191Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-0193Multiple vulnerabilities in the CLI parser of Cisco IOS XE S…
Are you affected by CVE-2018-0186?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
