CVE-2018-0374 describes a critical vulnerability in Cisco Policy Suite versions prior to 18.2.0, specifically impacting the Policy Builder database. This flaw, due to a lack of authentication, allows an unauthenticated, remote attacker to directly access and modify any data within the database. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low complexity, leading to complete compromise of confidentiality, integrity, and availability. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it's not listed in KEV, the vulnerability garnered significant community discussion and media coverage at the time, indicating its perceived importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:mobility_services_engine:14.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.