AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-0484

MEDIUM · CVSS 5.3 EPSS 0.79%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-01-10 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-0484
Severity
MEDIUM
CVSS
5.3
EPSS
0.79%
Cisco

Original NVD Description

A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration. The vulnerability is due to a missing check in the SSH server. An attacker could use this vulnerability to open an SSH connection to an affected Cisco IOS or IOS XE device with a source address belonging to a VRF instance. Once connected, the attacker would still need to provide valid credentials to access the device.