CVE-2018-0435 describes a critical vulnerability in the Cisco Umbrella API, affecting Cisco Umbrella products. This flaw stems from insufficient authentication configurations, allowing an authenticated, remote attacker to view and modify data across their own and other organizations. With a CVSS score of 9.1 (CRITICAL), the vulnerability is easily exploitable over the network with low complexity, requiring only low privileges, and can lead to significant impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered considerable community attention with 11 mentions and one media article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:cisco:umbrella:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.9 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.