CVE-2018-0376: Cisco Mobility Services Engine

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to access the Policy Builder interface. The vulnerability is due to a lack of authentication. An attacker could exploit this vulnerability by accessing the Policy Builder interface. A successful exploit could allow the attacker to make changes to existing repositories and create new repositories. Cisco Bug IDs: CSCvi35109.

Affected products

  • Cisco Mobility Services Engine: version 18.0.0 only
  • Cisco Policy Suite: before 18.2.0 (fixed in 18.2.0)

Published 2018-07-18. Last modified 2026-06-17.