CVE-2018-15439
Last modified
CVE-2018-15439 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. EPSS estimates a 49.74% chance of exploitation in the next 30 days.
Description
A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. An attacker could exploit this vulnerability by using this account to log in to an affected device and execute commands with full admin rights. Cisco has not released software updates that address this vulnerability. This advisory will be updated with fixed software information once fixed software becomes available. There is a workaround to address this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Sg200-50 Firmware | All versions |
| Cisco | Sg200-50p Firmware | All versions |
| Cisco | Sg200-50fp Firmware | All versions |
| Cisco | Sg200-26 Firmware | All versions |
| Cisco | Sg200-26p Firmware | All versions |
| Cisco | Sg200-26fp Firmware | All versions |
| Cisco | Sg200-18 Firmware | All versions |
| Cisco | Sg200-10fp Firmware | All versions |
| Cisco | Sg200-08 Firmware | All versions |
| Cisco | Sg200-08p Firmware | All versions |
| Cisco | Sf200-24 Firmware | All versions |
| Cisco | Sf200-24p Firmware | All versions |
| Cisco | Sf200-24fp Firmware | All versions |
| Cisco | Sf200-48 Firmware | All versions |
| Cisco | Sf200-48p Firmware | All versions |
| Cisco | Sf302-08pp Firmware | All versions |
| Cisco | Sf302-08mpp Firmware | All versions |
| Cisco | Sg300-10pp Firmware | All versions |
| Cisco | Sg300-10mpp Firmware | All versions |
| Cisco | Sf300-24pp Firmware | All versions |
| Cisco | Sf300-48pp Firmware | All versions |
| Cisco | Sg300-28pp Firmware | All versions |
| Cisco | Sf300-08 Firmware | All versions |
| Cisco | Sf300-48p Firmware | All versions |
| Cisco | Sg300-10mp Firmware | All versions |
| Cisco | Sg300-10p Firmware | All versions |
| Cisco | Sg300-10 Firmware | All versions |
| Cisco | Sg300-28p Firmware | All versions |
| Cisco | Sf300-24p Firmware | All versions |
| Cisco | Sf302-08mp Firmware | All versions |
| Cisco | Sg300-28 Firmware | All versions |
| Cisco | Sf300-48 Firmware | All versions |
| Cisco | Sg300-20 Firmware | All versions |
| Cisco | Sf302-08p Firmware | All versions |
| Cisco | Sg300-52 Firmware | All versions |
| Cisco | Sf300-24 Firmware | All versions |
| Cisco | Sf302-08 Firmware | All versions |
| Cisco | Sf300-24mp Firmware | All versions |
| Cisco | Sg300-10sfp Firmware | All versions |
| Cisco | Sg300-28mp Firmware | All versions |
| Cisco | Sg300-52p Firmware | All versions |
| Cisco | Sg300-52mp Firmware | All versions |
| Cisco | Sg500-28mpp Firmware | All versions |
| Cisco | Sg500-52mp Firmware | All versions |
| Cisco | Sg500xg-8f8t Firmware | All versions |
| Cisco | Sf500-24 Firmware | All versions |
| Cisco | Sf500-24p Firmware | All versions |
| Cisco | Sf500-48 Firmware | All versions |
| Cisco | Sf500-48p Firmware | All versions |
| Cisco | Sg500-28 Firmware | All versions |
Showing 50 of 114 affected configurations. See NVD for the full list.
References
- http://www.securityfocus.com/bid/105873Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/105873Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15439?
How severe is CVE-2018-15439?
How do I fix CVE-2018-15439?
Are you affected by CVE-2018-15439?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
