PT-2018-8826 · Cisco · Cisco Umbrella
Publicado
2018-10-05
·
Atualizado
2019-10-09
·
CVE-2018-0435
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Umbrella (affected versions not specified)
Description
A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organizations. The issue is due to insufficient authentication configurations for the API interface of Cisco Umbrella. An attacker could exploit this to view and potentially modify data for their organization or other organizations, allowing them to read or modify data across multiple organizations.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Umbrella