CVE-2018-0463 is a high-severity vulnerability in the Cisco Network Plug and Play server component of Cisco Network Services Orchestrator (NSO). It allows an unauthenticated, remote attacker to gain unauthorized access to configuration data due to incomplete validation when SUDI authentication is used. The attack requires an attacker-controlled Cisco device with SUDI support and connectivity to the NSO system, leveraging information about registered devices to send crafted authentication packets. A successful exploit could lead to unauthorized access to configuration data for devices managed by the NSO system. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:network_services_orchestrator:1.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.