CVE-2018-0377 is a critical vulnerability affecting Cisco Policy Suite versions prior to 18.1.0, and also Cisco Mobility Services Engine. It allows unauthenticated, remote attackers to directly access the OSGi interface due to a lack of authentication. This vulnerability carries a CVSS score of 9.8 (Critical), indicating a high-impact threat where an attacker could gain full control over files accessible by the OSGi process. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with 12 mentions and two media articles, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:mobility_services_engine:14.0.0:*:*:*:*:*:*:* | ||
< 18.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:policy_suite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.