CVE-2018-0484
Description
A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration. The vulnerability is due to a missing check in the SSH server. An attacker could use this vulnerability to open an SSH connection to an affected Cisco IOS or IOS XE device with a source address belonging to a VRF instance. Once connected, the attacker would still need to provide valid credentials to access the device.
- CVSS Version 3.0
- CVSS Version 2.0
nvd
CVE ID: CVE-2018-0484
Base Score: 6.5
Base Severity: MEDIUM
Vector String:CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
cisco
CVE ID: CVE-2018-0484
Base Score: 5.3
Base Severity: MEDIUM
Vector String:CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd
CVE ID: CVE-2018-0484
Base Score: 4.0
Base Severity: MEDIUM
Vector String:AV:N/AC:L/Au:S/C:N/I:P/A:N