PT-2018-1030 · Cisco · Cisco Elastic Services Controller

Published

2018-02-21

·

Updated

2019-10-09

·

CVE-2018-0121

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Elastic Services Controller Software Release 3.0.0
Description A vulnerability in the authentication functionality of the web-based service portal could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The issue is due to improper security restrictions imposed by the web-based service portal. An attacker could exploit this by submitting an empty password value when prompted to enter an administrative password, potentially gaining administrator privileges for the web-based service portal.
Recommendations For Cisco Elastic Services Controller Software Release 3.0.0, consider restricting access to the web-based service portal until a fix is available, and avoid using empty password values to prevent exploitation. As a temporary workaround, consider disabling the administrative password prompt for the portal until a patch is available.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00325
CVE-2018-0121

Affected Products

Cisco Elastic Services Controller