Access Control Vulnerability in Cisco Policy Suite CLI
CVE-2018-0392
5.5MEDIUM
Summary
A vulnerability in the Command-Line Interface (CLI) of Cisco Policy Suite allows an authenticated local attacker to exploit insufficient access control permissions. This situation arises when files are unintentionally set to be world-readable, enabling unauthorized access to potentially sensitive information owned by other users. An attacker can take advantage of this flaw by logging into the CLI and accessing these vulnerable files. It is essential for users of Cisco Policy Suite to understand the risks associated with this vulnerability and implement necessary security measures.
Affected Version(s)
Cisco Policy Suite unknown Cisco Policy Suite unknown
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved