← Vulnerability feed

Vulnerability record · CVE-2018-0121 · published 22 February 2018

CVE-2018-0121: Cisco elastic services controller improper authentication vulnerability

Cisco · Elastic Services Controller

A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper security restrictions that are imposed by the web-based service portal of the affected software. An attacker could exploit this vulnerability by submitting an empty password value to an affected portal when prompted to enter an administrative password for the portal. A successful exploit could allow the attacker to bypass authentication and gain administrator privileges for the web-based service portal of the affected software. This vulnerability affects Cisco Elastic Services Controller Software Release 3.0.0. Cisco Bug IDs: CSCvg29809.

9.8 CVSS 3.0 Critical EPSS 2.5% · top 15.8% CWE-287 · Improper authentication
9.8CVSS 3.0 base score, v2 7.5
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper security restrictions that are imposed by the web-based service portal of the affected software. An attacker could exploit this vulnerability by submitting an empty password value to an affected portal when prompted to enter an administrative password for the portal. A successful exploit could allow the attacker to bypass authentication and gain administrator privileges for the web-based service portal of the affected software. This vulnerability affects Cisco Elastic Services Controller Software Release 3.0.0. Cisco Bug IDs: CSCvg29809.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0121 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-1867Cisco elastic services controller improper authentication vulnerabilityA vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication o…EPSS 30%9.8CVE-2018-0130Cisco virtual managed services permissions and access controls vulnerabilityA vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenti…EPSS 1.9%9.8CVE-2017-6713Cisco elastic services controller permissions and access controls vulnerabilityA vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access …EPSS 2.9%8.8CVE-2017-6712Cisco elastic services controller os command injection vulnerabilityA vulnerability in certain commands of Cisco Elastic Services Controller could allow an authenticated, remote attacker to elevate privileges to root …EPSS 2.0%8.8CVE-2017-6682Cisco elastic services controller os command injection vulnerabilityA vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the…EPSS 2.2%8.8CVE-2017-6683Cisco elastic services controller os command injection vulnerabilityA vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrar…EPSS 5.9%8.8CVE-2017-6684Cisco elastic services controller insecure default initialization vulnerabilityA vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admi…EPSS 2.3%8.8CVE-2017-6688Cisco elastic services controller insecure default initialization vulnerabilityA vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2018-0121), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.