Back

CVE-2018-0124

CRITICAL

A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute arbitrary code. The vulnerability is due to insecure key generation during application configuration. An attacker could exploit this vulnerability by using a known insecure key value to bypass security protections by sending arbitrary requests using the insecure key to a targeted application. An exploit could allow the attacker to execute arbitrary code. This vulnerability affects Cisco Unified Communications Domain Manager releases prior to 11.5(2). Cisco Bug IDs: CSCuv67964.

Published: Feb 22, 2018 Modified: Jun 17, 2026
CWE-320 CWE-320

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
cisco unified_communications_domain_manager * < 11.5\(2\)

GitHub Security Advisory GHSA-8wjv-jcjm-9fj9

A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated,...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.06%

Top 8% most likely to be exploited

Threat Score 40.7 / 100

Data Sources

NVD EPSS GitHub