PT-2018-1030 · Cisco · Cisco Elastic Services Controller
Published
2018-02-21
·
Updated
2019-10-09
·
CVE-2018-0121
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Elastic Services Controller Software Release 3.0.0
Description
A vulnerability in the authentication functionality of the web-based service portal could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The issue is due to improper security restrictions imposed by the web-based service portal. An attacker could exploit this by submitting an empty password value when prompted to enter an administrative password, potentially gaining administrator privileges for the web-based service portal.
Recommendations
For Cisco Elastic Services Controller Software Release 3.0.0, consider restricting access to the web-based service portal until a fix is available, and avoid using empty password values to prevent exploitation. As a temporary workaround, consider disabling the administrative password prompt for the portal until a patch is available.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Elastic Services Controller