CVE-2018-0095 is a privilege escalation vulnerability in the administrative shell of Cisco AsyncOS, affecting Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA). An authenticated local attacker, even with guest-level credentials, can exploit an incorrect networking configuration to gain root access. This vulnerability has a CVSS score of 7.8 (High) due to its low attack complexity and significant impact on confidentiality, integrity, and availability. While no public exploit code or Metasploit modules are available, the vulnerability has received some community discussion and media coverage, though it is not currently listed on the KEV catalog or considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.1.1-005CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:9.1.1-005:*:*:*:*:*:*:* | ||
9.7.2-065CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:9.7.2-065:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.