CVE-2018-0393 (CNNVD-201807-1290)
中文标题:
Cisco Policy Suite 安全漏洞
英文标题:
A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite c...
漏洞描述
中文描述:
Cisco Policy Suite(CPS)是美国思科(Cisco)公司的一套下一代策略管理解决方案。该方案提供了基于用户的业务规则、应用程序和网络资源的实时管理等功能。 Cisco Policy Suite中的Policy Builder界面存在安全漏洞,该漏洞源于程序没有充分的执行授权控制。远程攻击者可通过访问Policy Builder界面并修改HTTP请求利用该漏洞更改现有的策略。
英文描述:
A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by accessing the Policy Builder interface and modifying an HTTP request. A successful exploit could allow the attacker to make changes to existing policies. Cisco Bug IDs: CSCvi35007.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | mobility_services_engine_3365_firmware | 18.0.0 | - | - |
cpe:2.3:o:cisco:mobility_services_engine_3365_firmware:18.0.0:*:*:*:*:*:*:*
|
| cisco | mobility_services_engine_3355_firmware | 18.0.0 | - | - |
cpe:2.3:o:cisco:mobility_services_engine_3355_firmware:18.0.0:*:*:*:*:*:*:*
|
| cisco | mobility_services_engine_3310_firmware | 18.0.0 | - | - |
cpe:2.3:o:cisco:mobility_services_engine_3310_firmware:18.0.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2018-0393 |
2025-11-11 15:19:35 | 2025-11-11 07:34:57 |
| NVD | nvd_CVE-2018-0393 |
2025-11-11 14:55:57 | 2025-11-11 07:43:33 |
| CNNVD | cnnvd_CNNVD-201807-1290 |
2025-11-11 15:10:03 | 2025-11-11 07:53:49 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-201807-1290
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 6.5
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']