Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2018-0130
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to gain administrative access to an affected system. The vulnerability is due to the presence of static default credentials for the web-based service portal of the affected software. An attacker could exploit this vulnerability by extracting the credentials from an image of the affected software and using those credentials to generate a valid administrative session token for the web-based service portal of any other installation of the affected software. A successful exploit could allow the attacker to gain administrative access to the web-based service portal of an affected system. This vulnerability affects Cisco Elastic Services Controller Software Release 3.0.0. Cisco Bug IDs: CSCvg30884.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
权限、特权和访问控制
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco Elastic Services Controller Software 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Elastic Services Controller Software(ESC)是美国思科(Cisco)公司的一套开源的用于管理虚拟资源的模块化系统。service portal是其中的一个基于Web的业务系统门户。 Cisco ESC 3.0.0版本中基于Web的业务门户的JSON Web令牌使用存在安全漏洞,该漏洞源于程序为基于Web的服务门户使用了静态的默认凭证。远程攻击攻击者可通过从受影响软件的图像中提取凭证,并使用这些凭证创建有效的管理会话令牌利用该漏洞获取基于Web服务门户的管理
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-Cisco Elastic Services Controller Cisco Elastic Services Controller -
II. Public POCs for CVE-2018-0130
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2018-0130
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2018-0130

No comments yet


Leave a comment