CVE-2018-0362
4.3
Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 0.9 / Impact: 3.4
Source: NVD
Description
A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attacker to bypass the BIOS authentication and execute actions as an unprivileged user. The vulnerability is due to improper security restrictions that are imposed by the affected system. An attacker could exploit this vulnerability by submitting an empty password value to an affected device's BIOS authentication prompt. An exploit could allow the attacker to have access to a restricted set of user-level BIOS commands. Cisco Bug IDs: CSCvh83260.
Affected (21)
Products: Cisco: 5400 Enterprise Network Compute System Firmware, 5100 Enterprise Network Compute System Firmware, Ucs E160s M3 Firmware, Ucs E160s K9 Firmware, Ucs E180d M3 Firmware, Ucs E1120d M3 Firmware, Ucs E1120d K9 Firmware, Ucs E140s M2 Firmware, Ucs E160d M2 Firmware, Ucs E180d M2 Firmware, Ucs E180d K9 Firmware, Ucs E140s M1 Firmware, Ucs E140s K9 Firmware, Ucs E160d M1 Firmware, Ucs E160d K9 Firmware, Ucs E160dp M1 Firmware, Ucs E160dp K9 Firmware, Ucs E140d M1 Firmware, Ucs E140d K9 Firmware, Ucs E140dp M1 Firmware, Ucs E140dp K9 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco 5400 Enterprise Network Compute System | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco 5100 Enterprise Network Compute System | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E160s M3 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E160s K9 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E180d M3 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E1120d M3 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E1120d K9 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140s M2 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E160d M2 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E180d M2 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E180d K9 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140s M1 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140s K9 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E160d M1 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E160d K9 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E160dp M1 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E160dp K9 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140d M1 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140d K9 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140dp M1 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2(3) |
| Running on/with | Platform Versions |
|---|---|
Cisco Ucs E140dp K9 | All versions |
References (4)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.