CVE-2018-0364 is a Cross-Site Request Forgery (CSRF) vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager. This flaw, rated 8.8 HIGH on the CVSS scale, allows an unauthenticated, remote attacker to trick an authenticated user into executing arbitrary actions on the device. Exploitation requires user interaction via a crafted link, and a successful attack grants the attacker the privileges of the compromised user. There is currently no public exploit code available, and the vulnerability has received minimal community discussion or media coverage, indicating no active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_domain_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.