Privilege Escalation Vulnerability in Cisco Email Security Appliance
CVE-2018-0095
7.8HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 18 January 2018
Summary
A flaw in the administrative shell of Cisco's Email Security Appliance and Content Security Management Appliance enables an authenticated local attacker to escalate their privileges. By exploiting improper configurations in the command-line interface, attackers with guest-level credentials can execute malicious commands that grant them root access. This issue stems from a misconfiguration that opens pathways for unauthorized control, posing significant risks to device security. Cisco Bug IDs associated with this issue include CSCvb34303 and CSCvb35726.
Affected Version(s)
Cisco Email Security and Content Security Management Appliance Cisco Email Security and Content Security Management Appliance
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved