CVE-2018-4007 is a privilege escalation vulnerability in the Shimo VPN 4.1.5.1 helper service's deleteConfig functionality, allowing an authenticated local attacker to delete any protected file on the system. With a CVSS score of 7.1 (High), this vulnerability has a low attack complexity and requires local access, but can lead to high impact on integrity and availability. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, with only one mention and one article, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.5.1CPE matchmatch criteria | cpe:2.3:a:shimovpn:shimo_vpn:4.1.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.