← Vulnerability feed

Vulnerability record · CVE-2018-0270 · published 17 May 2018

CVE-2018-0270: Cisco iot field network director cross-site request forgery vulnerability

Cisco · Iot Field Network Director

A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and alter the data of existing users and groups on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. If the user has administrative privileges, the attacker could create a new, privileged account to obtain full control over the device interface. This vulnerability affects Connected Grid Network Management System, if running a software release prior to IoT-FND Release 3.0; and IoT Field Network Director, if running a software release prior to IoT-FND Release 4.1.1-6 or 4.2.0-123. Cisco Bug IDs: CSCvi02448.

8.8 CVSS 3.0 High EPSS 0.68% · top 49.4% CWE-352 · Cross-site request forgery
8.8CVSS 3.0 base score, v2 6.8
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and alter the data of existing users and groups on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. If the user has administrative privileges, the attacker could create a new, privileged account to obtain full control over the device interface. This vulnerability affects Connected Grid Network Management System, if running a software release prior to IoT-FND Release 3.0; and IoT Field Network Director, if running a software release prior to IoT-FND Release 4.1.1-6 or 4.2.0-123. Cisco Bug IDs: CSCvi02448.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0270 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2020-3531Cisco iot field network director missing authentication for critical function vulnerabilityA vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end data…EPSS 2.2%8.8CVE-2020-26075Cisco iot field network director sql injection vulnerabilityA vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to gain access to the back-en…EPSS 1.6%8.7CVE-2020-26072Cisco iot field network director improper access control vulnerabilityA vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify informat…EPSS 1.0%7.7CVE-2026-20167Cisco iot field network director improper access control vulnerabilityA vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low priv…EPSS 0.27%7.5CVE-2020-3392Cisco iot field network director missing authentication for critical function vulnerabilityA vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on…EPSS 1.5%7.5CVE-2020-26076Cisco iot field network director information exposure vulnerabilityA vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on a…EPSS 1.3%7.5CVE-2020-3162Cisco iot field network director improper input validation vulnerabilityA vulnerability in the Constrained Application Protocol (CoAP) implementation of Cisco IoT Field Network Director could allow an unauthenticated remo…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2018-0270), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.