PT-2018-8826 · Cisco · Cisco Umbrella

Publicado

2018-10-05

·

Atualizado

2019-10-09

·

CVE-2018-0435

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco Umbrella (affected versions not specified)
Description A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organizations. The issue is due to insufficient authentication configurations for the API interface of Cisco Umbrella. An attacker could exploit this to view and potentially modify data for their organization or other organizations, allowing them to read or modify data across multiple organizations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-0435

Produtos afetados

Cisco Umbrella