PT-2018-8826 · Cisco · Cisco Umbrella

Published

2018-10-05

·

Updated

2019-10-09

·

CVE-2018-0435

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco Umbrella (affected versions not specified)
Description A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organizations. The issue is due to insufficient authentication configurations for the API interface of Cisco Umbrella. An attacker could exploit this to view and potentially modify data for their organization or other organizations, allowing them to read or modify data across multiple organizations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0435

Affected Products

Cisco Umbrella