CVE-2018-0226 describes a privilege escalation vulnerability in Cisco Aironet 1800, 2800, and 3800 Series Access Points running Cisco Mobility Express Software. This flaw allows an authenticated, remote attacker to gain administrative privileges on an affected access point due to improper assignment of default SSH user accounts. With a CVSS score of 7.5 (HIGH), exploitation requires valid user credentials but can lead to full administrative control over the access point. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.3\(90.65\)CPE matchmatch criteria | cpe:2.3:o:cisco:mobility_express_software:8.3\(90.65\):*:*:*:*:*:*:* | ||
8.4\(1.65\)CPE matchmatch criteria | cpe:2.3:o:cisco:mobility_express_software:8.4\(1.65\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.