Privilege Escalation Vulnerability in Cisco Email Security Appliance
CVE-2018-0095

7.8HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
18 January 2018

Summary

A flaw in the administrative shell of Cisco's Email Security Appliance and Content Security Management Appliance enables an authenticated local attacker to escalate their privileges. By exploiting improper configurations in the command-line interface, attackers with guest-level credentials can execute malicious commands that grant them root access. This issue stems from a misconfiguration that opens pathways for unauthorized control, posing significant risks to device security. Cisco Bug IDs associated with this issue include CSCvb34303 and CSCvb35726.

Affected Version(s)

Cisco Email Security and Content Security Management Appliance Cisco Email Security and Content Security Management Appliance

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.