CVE Database
/

CVE-2018-0095

Back to search

CVE-2018-0095

Published: Jan 18, 2018

Modified: Dec 2, 2024

PUBLISHED

Description

A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a privilege level of a guest user. The vulnerability is due to an incorrect networking configuration at the administrative shell CLI. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a set of crafted, malicious commands at the administrative shell. An exploit could allow the attacker to gain root access on the device. Cisco Bug IDs: CSCvb34303, CSCvb35726.

VendorProductVersions

n/a

Cisco Email Security and Content Security Management Appliance

affected
Cisco Email Security and Content Security Management Appliance

Weaknesses (CWE)

References

1040221
vdb-entry
x_refsource_SECTRACK
1040222
vdb-entry
x_refsource_SECTRACK
102729
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now