Unauthorized Access Vulnerability in Cisco Policy Suite by Cisco
CVE-2018-0089
7.5HIGH
Summary
A vulnerability exists in the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite, allowing unauthorized remote access to sensitive data. An attacker needs to be connected to the internal VLAN where the CPS is deployed. This vulnerability arises from improper permissions on certain system files and inadequate protection of sensitive data stored within the system. By exploiting this, an attacker can utilize network tools to access confidential system files, potentially leveraging revealed information for further malicious activities.
Affected Version(s)
Cisco Policy Suite Cisco Policy Suite
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved