← Vulnerability feed

Vulnerability record · CVE-2018-15439 · published 8 November 2018

CVE-2018-15439: Cisco Small Business Switches authentication bypass via hidden privileged account

Cisco · Sg200 50 Firmware

Cisco Small Business Switches software can enable a privileged user account under specific circumstances without notifying administrators, creating a hard-coded credential condition (CWE-798). An unauthenticated remote attacker can use that account to log in and run commands with full admin rights. Cisco had not released fixed software at the time of the advisory, though a workaround exists.

9.8 CVSS 3.1 Critical EPSS 50% · top 1.1% CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score, v2 9.3
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
114Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. An attacker could exploit this vulnerability by using this account to log in to an affected device and execute commands with full admin rights. Cisco has not released software updates that address this vulnerability. This advisory will be updated with fixed software information once fixed software becomes available. There is a workaround to address this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, full confidentiality, integrity and availability impact, and no vendor patch available at disclosure.

What it is

Cisco Small Business Switches software can enable a privileged user account under specific circumstances without notifying administrators, creating a hard-coded credential condition (CWE-798). An unauthenticated remote attacker can use that account to log in and run commands with full admin rights. Cisco had not released fixed software at the time of the advisory, though a workaround exists.

Impact

An attacker gains full administrative control of the affected switch, allowing configuration changes, traffic interception or redirection, and disruption of the network segment it serves. No prior credentials or privileges are required.

Attack surface

Reachable over the network via the switch management interface, as reflected by the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is needed; the attacker only needs network access to the device.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is high at roughly 0.497 (98.8th percentile), indicating elevated predicted exploitation activity.

What to do

  • Apply the fixed software once Cisco publishes it; the advisory states no update was available at release, so monitor the vendor advisory for updates.
  • Apply the Cisco-documented workaround for this vulnerability in the interim.
  • Restrict management access to the switch to trusted internal networks and disable remote management from untrusted or internet-facing interfaces.
  • Audit local accounts on affected switches and remove or disable any unexpected privileged accounts.
  • Monitor the vendor advisory and CISA channels for updated fixed-software information.

Detection

  • Alert on successful logins to switch management interfaces from unexpected source IPs or at unusual times.
  • Audit local user account tables on affected switches for accounts not created by administrators.
  • Monitor configuration changes and privileged command execution on switches for activity outside change windows.
  • Review authentication logs for logins using accounts that do not map to known administrators.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

114 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15439 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-20189Cisco business 250-16p-2g firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attac…EPSS 11%9.8CVE-2023-20157Cisco business 250-16p-2g firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attac…EPSS 1.2%9.8CVE-2023-20158Cisco business 250-16p-2g firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attac…EPSS 1.2%9.8CVE-2023-20159Cisco business 250-16p-2g firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attac…EPSS 10%9.8CVE-2023-20160Cisco business 250-16p-2g firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attac…EPSS 10%9.8CVE-2023-20161Cisco business 250-16p-2g firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attac…EPSS 10%9.8CVE-2023-20162Cisco business 250-16p-2g firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attac…EPSS 1.2%9.8CVE-2023-20156Cisco business 250-16p-2g firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attac…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2018-15439), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.