← Back to browse · API

CVE-2018-15394

Severity
CRITICAL
CVSS
9.8
EPSS
0.04021
Risk score
40.61
CISA KEV
No
PoC
No
Published
2018-11-08
Modified
2024-11-26
First seen
2026-08-07
Aliases
EUVD-2018-7272, GHSA-QG74-X86Q-MR5X
Products
Cisco:Cisco Stealthwatch Enterprise n/a
Sources
euvd EUVD-2018-7272

Description

A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected system. The vulnerability is due to an insecure system configuration. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. An exploit could allow the attacker to gain unauthenticated access, resulting in elevated privileges in the SMC.

References