SB2018062110 - Authentication bypass in Cisco 5000 Series ENCS and Cisco UCS E-Series Servers
Published: June 21, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Authentication bypass (CVE-ID: CVE-2018-0362)
The vulnerability allows a local unauthenticated attacker to bypass authentication on the target system.
The vulnerability exists in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers due to improper security restrictions. A local attacker can submit an empty password value to an affected device's BIOS authentication prompt, bypass authentication and gain access to a restricted set of user-level BIOS commands.
Remediation
Install update from vendor's website.