CVE-2018-15439
Description
A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. An attacker could exploit this vulnerability by using this account to log in to an affected device and execute commands with full admin rights. Cisco has not released software updates that address this vulnerability. This advisory will be updated with fixed software information once fixed software becomes available. There is a workaround to address this vulnerability.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Use of Hard-coded Credentials
DraftCommon Consequences
Applicable Platforms
Sg250-26Hp Firmware by Cisco
cpe:2.3:o:cisco:sg250-26hp_firmware:-:*:*:*:*:*:*:*
Sx550X-52 Firmware by Cisco
cpe:2.3:o:cisco:sx550x-52_firmware:-:*:*:*:*:*:*:*
Sg200-50P Firmware by Cisco
cpe:2.3:o:cisco:sg200-50p_firmware:-:*:*:*:*:*:*:*
Sg200-26P Firmware by Cisco
cpe:2.3:o:cisco:sg200-26p_firmware:-:*:*:*:*:*:*:*
Sg250-50Hp Firmware by Cisco
cpe:2.3:o:cisco:sg250-50hp_firmware:-:*:*:*:*:*:*:*
Sf500-24P Firmware by Cisco
cpe:2.3:o:cisco:sf500-24p_firmware:-:*:*:*:*:*:*:*
Sf250-48 Firmware by Cisco
cpe:2.3:o:cisco:sf250-48_firmware:-:*:*:*:*:*:*:*
Sf550X-48P Firmware by Cisco
cpe:2.3:o:cisco:sf550x-48p_firmware:-:*:*:*:*:*:*:*
Sf300-08 Firmware by Cisco
cpe:2.3:o:cisco:sf300-08_firmware:-:*:*:*:*:*:*:*
Sg500Xg-8F8T Firmware by Cisco
cpe:2.3:o:cisco:sg500xg-8f8t_firmware:-:*:*:*:*:*:*:*
Sf550X-48 Firmware by Cisco
cpe:2.3:o:cisco:sf550x-48_firmware:-:*:*:*:*:*:*:*
Sg200-26 Firmware by Cisco
cpe:2.3:o:cisco:sg200-26_firmware:-:*:*:*:*:*:*:*
Sg250-50P Firmware by Cisco
cpe:2.3:o:cisco:sg250-50p_firmware:-:*:*:*:*:*:*:*
Sg350X-24Mp Firmware by Cisco
cpe:2.3:o:cisco:sg350x-24mp_firmware:-:*:*:*:*:*:*:*
Sf550X-24 Firmware by Cisco
cpe:2.3:o:cisco:sf550x-24_firmware:-:*:*:*:*:*:*:*
Sf550X-24Mp Firmware by Cisco
cpe:2.3:o:cisco:sf550x-24mp_firmware:-:*:*:*:*:*:*:*
Sf300-24Mp Firmware by Cisco
cpe:2.3:o:cisco:sf300-24mp_firmware:-:*:*:*:*:*:*:*
Sg200-08 Firmware by Cisco
cpe:2.3:o:cisco:sg200-08_firmware:-:*:*:*:*:*:*:*
Sg300-28P Firmware by Cisco
cpe:2.3:o:cisco:sg300-28p_firmware:-:*:*:*:*:*:*:*
Sg300-10P Firmware by Cisco
cpe:2.3:o:cisco:sg300-10p_firmware:-:*:*:*:*:*:*:*
Sg350-10P Firmware by Cisco
cpe:2.3:o:cisco:sg350-10p_firmware:-:*:*:*:*:*:*:*
Sg300-28Mp Firmware by Cisco
cpe:2.3:o:cisco:sg300-28mp_firmware:-:*:*:*:*:*:*:*
Sg300-52Mp Firmware by Cisco
cpe:2.3:o:cisco:sg300-52mp_firmware:-:*:*:*:*:*:*:*
Sg350-28P Firmware by Cisco
cpe:2.3:o:cisco:sg350-28p_firmware:-:*:*:*:*:*:*:*
Sg250X-24P Firmware by Cisco
cpe:2.3:o:cisco:sg250x-24p_firmware:-:*:*:*:*:*:*:*
Sg300-28 Firmware by Cisco
cpe:2.3:o:cisco:sg300-28_firmware:-:*:*:*:*:*:*:*
Sg250X-48 Firmware by Cisco
cpe:2.3:o:cisco:sg250x-48_firmware:-:*:*:*:*:*:*:*
Sg500-52P Firmware by Cisco
cpe:2.3:o:cisco:sg500-52p_firmware:-:*:*:*:*:*:*:*
Sf250-24P Firmware by Cisco
cpe:2.3:o:cisco:sf250-24p_firmware:-:*:*:*:*:*:*:*
Sg350Xg-2F10 Firmware by Cisco
cpe:2.3:o:cisco:sg350xg-2f10_firmware:-:*:*:*:*:*:*:*
Sf200-24P Firmware by Cisco
cpe:2.3:o:cisco:sf200-24p_firmware:-:*:*:*:*:*:*:*
Sf200-48 Firmware by Cisco
cpe:2.3:o:cisco:sf200-48_firmware:-:*:*:*:*:*:*:*
Sg200-50Fp Firmware by Cisco
cpe:2.3:o:cisco:sg200-50fp_firmware:-:*:*:*:*:*:*:*
Sg500-28 Firmware by Cisco
cpe:2.3:o:cisco:sg500-28_firmware:-:*:*:*:*:*:*:*
Sg250-10P Firmware by Cisco
cpe:2.3:o:cisco:sg250-10p_firmware:-:*:*:*:*:*:*:*
Sg350-28Mp Firmware by Cisco
cpe:2.3:o:cisco:sg350-28mp_firmware:-:*:*:*:*:*:*:*
Sg250-26 Firmware by Cisco
cpe:2.3:o:cisco:sg250-26_firmware:-:*:*:*:*:*:*:*
Sg300-10 Firmware by Cisco
cpe:2.3:o:cisco:sg300-10_firmware:-:*:*:*:*:*:*:*
Sg250-08 Firmware by Cisco
cpe:2.3:o:cisco:sg250-08_firmware:-:*:*:*:*:*:*:*
Sg250X-24 Firmware by Cisco
cpe:2.3:o:cisco:sg250x-24_firmware:-:*:*:*:*:*:*:*
Sg500-28Mpp Firmware by Cisco
cpe:2.3:o:cisco:sg500-28mpp_firmware:-:*:*:*:*:*:*:*
Sg500-52 Firmware by Cisco
cpe:2.3:o:cisco:sg500-52_firmware:-:*:*:*:*:*:*:*
Sg300-10Sfp Firmware by Cisco
cpe:2.3:o:cisco:sg300-10sfp_firmware:-:*:*:*:*:*:*:*
Sg550X-24 Firmware by Cisco
cpe:2.3:o:cisco:sg550x-24_firmware:-:*:*:*:*:*:*:*
Sg550X-48 Firmware by Cisco
cpe:2.3:o:cisco:sg550x-48_firmware:-:*:*:*:*:*:*:*
Sg350Xg-24F Firmware by Cisco
cpe:2.3:o:cisco:sg350xg-24f_firmware:-:*:*:*:*:*:*:*
Sg550X-48P Firmware by Cisco
cpe:2.3:o:cisco:sg550x-48p_firmware:-:*:*:*:*:*:*:*
Sg350X-24P Firmware by Cisco
cpe:2.3:o:cisco:sg350x-24p_firmware:-:*:*:*:*:*:*:*
Sg550X-48Mp Firmware by Cisco
cpe:2.3:o:cisco:sg550x-48mp_firmware:-:*:*:*:*:*:*:*
Sx550X-24 Firmware by Cisco
cpe:2.3:o:cisco:sx550x-24_firmware:-:*:*:*:*:*:*:*
Sf300-24P Firmware by Cisco
cpe:2.3:o:cisco:sf300-24p_firmware:-:*:*:*:*:*:*:*
Sf550X-48Mp Firmware by Cisco
cpe:2.3:o:cisco:sf550x-48mp_firmware:-:*:*:*:*:*:*:*
Sf302-08Mpp Firmware by Cisco
cpe:2.3:o:cisco:sf302-08mpp_firmware:-:*:*:*:*:*:*:*
Sg350X-24 Firmware by Cisco
cpe:2.3:o:cisco:sg350x-24_firmware:-:*:*:*:*:*:*:*
Sx550X-24F Firmware by Cisco
cpe:2.3:o:cisco:sx550x-24f_firmware:-:*:*:*:*:*:*:*
Sf250-24 Firmware by Cisco
cpe:2.3:o:cisco:sf250-24_firmware:-:*:*:*:*:*:*:*
Sf250-48Hp Firmware by Cisco
cpe:2.3:o:cisco:sf250-48hp_firmware:-:*:*:*:*:*:*:*
Sg250-08Hp Firmware by Cisco
cpe:2.3:o:cisco:sg250-08hp_firmware:-:*:*:*:*:*:*:*
Sf300-48P Firmware by Cisco
cpe:2.3:o:cisco:sf300-48p_firmware:-:*:*:*:*:*:*:*
Sg550X-24P Firmware by Cisco
cpe:2.3:o:cisco:sg550x-24p_firmware:-:*:*:*:*:*:*:*
Sg250X-48P Firmware by Cisco
cpe:2.3:o:cisco:sg250x-48p_firmware:-:*:*:*:*:*:*:*
Sg500-52Mp Firmware by Cisco
cpe:2.3:o:cisco:sg500-52mp_firmware:-:*:*:*:*:*:*:*
Sf350-48Mp Firmware by Cisco
cpe:2.3:o:cisco:sf350-48mp_firmware:-:*:*:*:*:*:*:*
Sf300-24 Firmware by Cisco
cpe:2.3:o:cisco:sf300-24_firmware:-:*:*:*:*:*:*:*
Sg550X-24Mpp Firmware by Cisco
cpe:2.3:o:cisco:sg550x-24mpp_firmware:-:*:*:*:*:*:*:*
Sx550X-12F Firmware by Cisco
cpe:2.3:o:cisco:sx550x-12f_firmware:-:*:*:*:*:*:*:*
Sf300-24Pp Firmware by Cisco
cpe:2.3:o:cisco:sf300-24pp_firmware:-:*:*:*:*:*:*:*
Sf500-48P Firmware by Cisco
cpe:2.3:o:cisco:sf500-48p_firmware:-:*:*:*:*:*:*:*
Sg355-10P Firmware by Cisco
cpe:2.3:o:cisco:sg355-10p_firmware:-:*:*:*:*:*:*:*
Sg350X-48 Firmware by Cisco
cpe:2.3:o:cisco:sg350x-48_firmware:-:*:*:*:*:*:*:*
Sg350-10 Firmware by Cisco
cpe:2.3:o:cisco:sg350-10_firmware:-:*:*:*:*:*:*:*
Sg200-08P Firmware by Cisco
cpe:2.3:o:cisco:sg200-08p_firmware:-:*:*:*:*:*:*:*
Sf550X-24P Firmware by Cisco
cpe:2.3:o:cisco:sf550x-24p_firmware:-:*:*:*:*:*:*:*
Sg200-50 Firmware by Cisco
cpe:2.3:o:cisco:sg200-50_firmware:-:*:*:*:*:*:*:*
Sg550X-24Mp Firmware by Cisco
cpe:2.3:o:cisco:sg550x-24mp_firmware:-:*:*:*:*:*:*:*
Sf350-48 Firmware by Cisco
cpe:2.3:o:cisco:sf350-48_firmware:-:*:*:*:*:*:*:*
Sg300-10Mpp Firmware by Cisco
cpe:2.3:o:cisco:sg300-10mpp_firmware:-:*:*:*:*:*:*:*
Sg250-26P Firmware by Cisco
cpe:2.3:o:cisco:sg250-26p_firmware:-:*:*:*:*:*:*:*
Sg500X-48 Firmware by Cisco
cpe:2.3:o:cisco:sg500x-48_firmware:-:*:*:*:*:*:*:*
Sf302-08Mp Firmware by Cisco
cpe:2.3:o:cisco:sf302-08mp_firmware:-:*:*:*:*:*:*:*
Sg350Xg-24T Firmware by Cisco
cpe:2.3:o:cisco:sg350xg-24t_firmware:-:*:*:*:*:*:*:*
Sg300-20 Firmware by Cisco
cpe:2.3:o:cisco:sg300-20_firmware:-:*:*:*:*:*:*:*
Sg500X-24P Firmware by Cisco
cpe:2.3:o:cisco:sg500x-24p_firmware:-:*:*:*:*:*:*:*
Sx550X-16Ft Firmware by Cisco
cpe:2.3:o:cisco:sx550x-16ft_firmware:-:*:*:*:*:*:*:*
Sf302-08Pp Firmware by Cisco
cpe:2.3:o:cisco:sf302-08pp_firmware:-:*:*:*:*:*:*:*
Sg350X-48Mp Firmware by Cisco
cpe:2.3:o:cisco:sg350x-48mp_firmware:-:*:*:*:*:*:*:*
Sf200-48P Firmware by Cisco
cpe:2.3:o:cisco:sf200-48p_firmware:-:*:*:*:*:*:*:*
Sg300-28Pp Firmware by Cisco
cpe:2.3:o:cisco:sg300-28pp_firmware:-:*:*:*:*:*:*:*
Sg350-28 Firmware by Cisco
cpe:2.3:o:cisco:sg350-28_firmware:-:*:*:*:*:*:*:*
Sg250-50 Firmware by Cisco
cpe:2.3:o:cisco:sg250-50_firmware:-:*:*:*:*:*:*:*
Sf300-48Pp Firmware by Cisco
cpe:2.3:o:cisco:sf300-48pp_firmware:-:*:*:*:*:*:*:*
Sf302-08P Firmware by Cisco
cpe:2.3:o:cisco:sf302-08p_firmware:-:*:*:*:*:*:*:*
Sf500-48 Firmware by Cisco
cpe:2.3:o:cisco:sf500-48_firmware:-:*:*:*:*:*:*:*
Sf500-24 Firmware by Cisco
cpe:2.3:o:cisco:sf500-24_firmware:-:*:*:*:*:*:*:*
Sg300-52 Firmware by Cisco
cpe:2.3:o:cisco:sg300-52_firmware:-:*:*:*:*:*:*:*
Sg200-10Fp Firmware by Cisco
cpe:2.3:o:cisco:sg200-10fp_firmware:-:*:*:*:*:*:*:*
Sx550X-24Ft Firmware by Cisco
cpe:2.3:o:cisco:sx550x-24ft_firmware:-:*:*:*:*:*:*:*
Sg500-28P Firmware by Cisco
cpe:2.3:o:cisco:sg500-28p_firmware:-:*:*:*:*:*:*:*
Sf300-48 Firmware by Cisco
cpe:2.3:o:cisco:sf300-48_firmware:-:*:*:*:*:*:*:*
Sg300-52P Firmware by Cisco
cpe:2.3:o:cisco:sg300-52p_firmware:-:*:*:*:*:*:*:*
Sf302-08 Firmware by Cisco
cpe:2.3:o:cisco:sf302-08_firmware:-:*:*:*:*:*:*:*
Sg500X-48P Firmware by Cisco
cpe:2.3:o:cisco:sg500x-48p_firmware:-:*:*:*:*:*:*:*
Sg200-26Fp Firmware by Cisco
cpe:2.3:o:cisco:sg200-26fp_firmware:-:*:*:*:*:*:*:*
Sg250-18 Firmware by Cisco
cpe:2.3:o:cisco:sg250-18_firmware:-:*:*:*:*:*:*:*
Sf200-24Fp Firmware by Cisco
cpe:2.3:o:cisco:sf200-24fp_firmware:-:*:*:*:*:*:*:*
Sf200-24 Firmware by Cisco
cpe:2.3:o:cisco:sf200-24_firmware:-:*:*:*:*:*:*:*
Sg200-18 Firmware by Cisco
cpe:2.3:o:cisco:sg200-18_firmware:-:*:*:*:*:*:*:*
Sg300-10Pp Firmware by Cisco
cpe:2.3:o:cisco:sg300-10pp_firmware:-:*:*:*:*:*:*:*
Sg350X-48P Firmware by Cisco
cpe:2.3:o:cisco:sg350x-48p_firmware:-:*:*:*:*:*:*:*
Sg350-10Mp Firmware by Cisco
cpe:2.3:o:cisco:sg350-10mp_firmware:-:*:*:*:*:*:*:*
Sg350Xg-48T Firmware by Cisco
cpe:2.3:o:cisco:sg350xg-48t_firmware:-:*:*:*:*:*:*:*
Sg300-10Mp Firmware by Cisco
cpe:2.3:o:cisco:sg300-10mp_firmware:-:*:*:*:*:*:*:*
Sg500X-24 Firmware by Cisco
cpe:2.3:o:cisco:sg500x-24_firmware:-:*:*:*:*:*:*:*
Sf350-48P Firmware by Cisco
cpe:2.3:o:cisco:sf350-48p_firmware:-:*:*:*:*:*:*:*