Skip to content
COOEY

EXPOSURES › CVE-2018-0125

CVE-2018-0125

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-0125 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Cisco VPN routers had an unauthenticated remote code execution flaw in their web interface allowing attackers full system control.

An unauthenticated remote attacker could execute arbitrary code as root on Cisco VPN routers via a web interface vulnerability, granting full system control. This is a critical failure for DIB organizations relying on secure network access, as it directly enables lateral movement and data exfiltration. Organizations must ensure all Cisco VPN router firmware is patched to the latest version and monitor for exploitation attempts.

Shame score — A critical RCE vulnerability in a widely deployed network device was left unpatched long enough to be actively exploited in the wild, demonstrating severe negligence in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized