CVE-2018-0088 (CNNVD-201801-631)
中文标题:
Cisco Industrial Ethernet 4010 Series Switches Cisco IOS Software 安全漏洞
英文标题:
A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series ...
漏洞描述
中文描述:
Cisco Industrial Ethernet 4010 Series Switches是美国思科(Cisco)公司的一款交换机设备。Cisco IOS Software是运行在其中的一套操作系统。 Cisco Industrial Ethernet 4010 Series Switches中的Cisco IOS Software的diagnostic test CLI命令存在拒绝服务漏洞,该漏洞源于程序允许用户向内存中执行写入操作。已认证的本地攻击者可通过发送诊断测试的CLI命令利用该漏洞执行任意代码或造成拒绝服务。
英文描述:
A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cisco IOS Software could allow an authenticated, local attacker to impact the stability of the device. This could result in arbitrary code execution or a denial of service (DoS) condition. The attacker has to have valid user credentials at privilege level 15. The vulnerability is due to a diagnostic test CLI command that allows the attacker to write to the device memory. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a specific diagnostic test command at the CLI. An exploit could allow the attacker to overwrite system memory locations, which could have a negative impact on the stability of the device. Cisco Bug IDs: CSCvf71150.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | industrial_ethernet_4010_series_firmware | * | - | - |
cpe:2.3:o:cisco:industrial_ethernet_4010_series_firmware:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2018-0088 |
2025-11-11 15:19:35 | 2025-11-11 07:34:56 |
| NVD | nvd_CVE-2018-0088 |
2025-11-11 14:55:51 | 2025-11-11 07:43:33 |
| CNNVD | cnnvd_CNNVD-201801-631 |
2025-11-11 15:09:57 | 2025-11-11 07:53:32 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 权限许可和访问控制问题
- cnnvd_id: 未提取 -> CNNVD-201801-631
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 6.7
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']