CVE-2018-0298 describes a buffer overflow vulnerability in the web UI of Cisco FXOS and UCS Fabric Interconnect Software, impacting Firepower 4100/9300 and UCS 6200/6300 Series devices. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated, remote attacker to trigger a denial of service by sending a crafted HTTP/HTTPS packet to the management interface. While no public exploits (Metasploit, Nuclei, ExploitDB) are known and community discussion is minimal, the potential for a device reload makes it a significant concern for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0\(2\), < 3.1\(3a\)aCPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 1.1, < 1.1.4.169CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:*:*:*:*:*:*:*:* | ||
>= 2.0, < 2.0.1.135CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:*:*:*:*:*:*:*:* | ||
>= 1.1, < 1.1.4.179CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:*:*:*:*:*:*:*:* | ||
>= 2.0, < 2.0.1.153CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.