CVE-2018-12335: Ecos System Management Appliance

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipulate security relevant configurations, via unrestricted database access during Easy Enrollment.

Affected products

  • Ecos System Management Appliance: version 5.2.68 only

Published 2018-06-17. Last modified 2026-06-17.