Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2018-0088

Quick assessment

Affected
n/a Cisco IOS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cisco Industrial Ethernet 4010 Series Switches是美国思科(Cisco)公司的一款交换机设备。Cisco IOS Software是运行在其中的一套操作系统。 Cisco Industrial Ethernet 4010 Series Switches中的Cisco IOS Software的diagnostic test CLI命令存在拒绝服务漏洞,该漏洞源于程序允许用户向内存中执行写入操作。已认证的本地攻击者可通过发送诊断测试的CLI命令利用该漏洞执行任意代

AI Predicted 6.5 Difficulty: Easy EPSS 0.39% · P31
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2018-0088

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cisco IOS Software could allow an authenticated, local attacker to impact the stability of the device. This could result in arbitrary code execution or a denial of service (DoS) condition. The attacker has to have valid user credentials at privilege level 15. The vulnerability is due to a diagnostic test CLI command that allows the attacker to write to the device memory. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a specific diagnostic test command at the CLI. An exploit could allow the attacker to overwrite system memory locations, which could have a negative impact on the stability of the device. Cisco Bug IDs: CSCvf71150.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
资源管理错误
Source: CVE Program / CVE List V5
Vulnerability Title
Cisco Industrial Ethernet 4010 Series Switches Cisco IOS Software 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Industrial Ethernet 4010 Series Switches是美国思科(Cisco)公司的一款交换机设备。Cisco IOS Software是运行在其中的一套操作系统。 Cisco Industrial Ethernet 4010 Series Switches中的Cisco IOS Software的diagnostic test CLI命令存在拒绝服务漏洞,该漏洞源于程序允许用户向内存中执行写入操作。已认证的本地攻击者可通过发送诊断测试的CLI命令利用该漏洞执行任意代
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- Cisco IOS Cisco IOS -

II. Public POCs for CVE-2018-0088

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-0088

请登录查看更多情报信息。

Vendor Advisories for CVE-2018-0088 (2)

Same Patch Batch · n/a · 2018-01-18 · 44 CVEs total

CVE-2018-5772 Exiv2 安全漏洞
CVE-2016-6814 Apache Groovy 代码问题漏洞
CVE-2017-15869 LiveZilla 跨站脚本漏洞
CVE-2017-12729 Moxa SoftCMS Live Viewer SQL注入漏洞
CVE-2017-17860 Samsung Gear S2和S3 输入验证错误漏洞
CVE-2018-5776 WordPress MediaElement 跨站脚本漏洞
CVE-2012-6708 jQuery 跨站脚本漏洞
CVE-2015-9251 jQuery 跨站脚本漏洞
CVE-2016-10707 jQuery 安全漏洞
CVE-2018-5773 markdown2 跨站脚本漏洞
CVE-2014-2017 OXID eShop 安全漏洞
CVE-2018-5766 Libav 安全漏洞
CVE-2018-0115 Cisco ASR 5000 Series路由器Cisco StarOS操作系统命令注入漏洞
CVE-2018-0111 Cisco WebEx Meetings Server 信息泄露漏洞
CVE-2018-0110 Cisco WebEx Meetings Server 安全漏洞
CVE-2018-0109 Cisco WebEx Meetings Server 信息泄露漏洞
CVE-2018-0108 Cisco WebEx Meetings Server 信息泄露漏洞
CVE-2018-0107 Cisco Prime Service Catalog 跨站脚本漏洞
CVE-2018-0106 Cisco Elastic Services Controller 信息泄露漏洞
CVE-2018-0105 Cisco Unified Communications Manager 信息泄露漏洞

Showing top 20 of 44 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2018-0088

No comments yet


Leave a comment