CVE-2018-0481 is a critical vulnerability in the CLI parser of Cisco IOS XE Software, allowing an authenticated, local attacker with privileged EXEC mode access to execute commands with root privileges on the underlying Linux shell. This medium-severity flaw (CVSS 6.7) stems from improper sanitization of command arguments, leading to full compromise of confidentiality, integrity, and availability. While no public exploit code exists and it's not actively exploited, its mention in security articles and community discussions indicates awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.3\(3\)s3.16CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:15.3\(3\)s3.16:*:*:*:*:*:*:* | ||
16.7\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.7\(1\):*:*:*:*:*:*:* | ||
16.7.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.7.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.