PT-2018-1191 · Cisco · Cisco Ios Xe

Published

2018-03-28

·

Updated

2019-12-03

·

CVE-2018-0152

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software versions prior to the fixed version
Description The issue is related to the web-based user interface of Cisco IOS XE Software, where a vulnerability exists due to the software not resetting the privilege level for each web UI session. This could allow an authenticated, remote attacker to gain elevated privileges on an affected device by remotely accessing a VTY line to the device. A successful exploit could allow the attacker to access an affected device with the privileges of the user who previously logged in to the web UI. The vulnerability affects Cisco devices running a vulnerable release of Cisco IOS XE Software, with the HTTP Server feature enabled and authentication, authorization, and accounting (AAA) authorization not configured for EXEC sessions.
Recommendations For Cisco IOS XE Software versions prior to the fixed version, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the HTTP Server feature until a patch is available. Restrict access to VTY lines to minimize the risk of exploitation. Configure authentication, authorization, and accounting (AAA) authorization for EXEC sessions to reduce the attack surface.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00649
CVE-2018-0152

Affected Products

Cisco Ios Xe