CVE-2018-0362 is a medium-severity vulnerability affecting Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing E-Series Servers. It allows an unauthenticated, local attacker to bypass BIOS authentication by submitting an empty password, gaining access to a restricted set of user-level BIOS commands. The attack requires physical presence (AV:P) and has low impact on confidentiality, integrity, and availability (C:L/I:L/A:L). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2\(3\)CPE matchmatch criteria | cpe:2.3:o:cisco:5400_enterprise_network_compute_system_firmware:3.2\(3\):*:*:*:*:*:*:* | ||
3.2\(3\)CPE matchmatch criteria | cpe:2.3:o:cisco:5100_enterprise_network_compute_system_firmware:3.2\(3\):*:*:*:*:*:*:* | ||
3.2\(3\)CPE matchmatch criteria | cpe:2.3:o:cisco:ucs-e160s-m3_firmware:3.2\(3\):*:*:*:*:*:*:* | ||
3.2\(3\)CPE matchmatch criteria | cpe:2.3:o:cisco:ucs-e160s-k9_firmware:3.2\(3\):*:*:*:*:*:*:* | ||
3.2\(3\)CPE matchmatch criteria | cpe:2.3:o:cisco:ucs-e180d-m3_firmware:3.2\(3\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.