CVE-2018-0130 describes a critical vulnerability in Cisco Elastic Services Controller Software Release 3.0.0, specifically impacting its web-based service portal. This flaw stems from static default credentials used in JSON web token generation, allowing an unauthenticated, remote attacker to achieve administrative access. With a CVSS score of 9.8, exploitation is straightforward with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential impact remains severe.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:cisco:virtual_managed_services:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.