peter bassill · operator
$ cve CVE-2018-15439 JSON

CVE-2018-15439

9.8
CRITICAL · CVSS 3.1 · EPSS 49.7% (pctl 99)

Patch early

EPSS 49.7% — above the 10% action threshold.

Description

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. An attacker could exploit this vulnerability by using this account to log in to an affected device and execute commands with full admin rights. Cisco has not released software updates that address this vulnerability. This advisory will be updated with fixed software information once fixed software becomes available. There is a workaround to address this vulnerability.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS49.74% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2018-11-08
Last modified2026-06-17

Affected (40)

VendorProduct
ciscosf200-24
ciscosf200-24 firmware
ciscosf200-24fp
ciscosf200-24fp firmware
ciscosf200-24p
ciscosf200-24p firmware
ciscosf200-48
ciscosf200-48 firmware
ciscosf200-48p
ciscosf200-48p firmware
ciscosf300-24pp
ciscosf300-24pp firmware
ciscosf302-08mpp
ciscosf302-08mpp firmware
ciscosf302-08pp
ciscosf302-08pp firmware
ciscosg200-08
ciscosg200-08 firmware
ciscosg200-08p
ciscosg200-08p firmware
ciscosg200-10fp
ciscosg200-10fp firmware
ciscosg200-18
ciscosg200-18 firmware
ciscosg200-26
ciscosg200-26 firmware
ciscosg200-26fp
ciscosg200-26fp firmware
ciscosg200-26p
ciscosg200-26p firmware
ciscosg200-50
ciscosg200-50 firmware
ciscosg200-50fp
ciscosg200-50fp firmware
ciscosg200-50p
ciscosg200-50p firmware
ciscosg300-10mpp
ciscosg300-10mpp firmware
ciscosg300-10pp
ciscosg300-10pp firmware

References

→ the Explorer  ·  watch your stack  ·  NVD