PT-2018-10805 · Puppet · Cisco Ios Module

Publicado

2018-10-02

·

Atualizado

2019-01-02

·

CVE-2018-11750

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Puppet cisco ios module versions prior to 0.4.0
Description The issue concerns the lack of host identity validation before establishing a SSH connection. This has been addressed in the 0.4.0 release of the cisco ios module, where host key checking is enabled by default.
Recommendations For versions prior to 0.4.0, update to version 0.4.0 or later to enable host key checking by default.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11750

Produtos afetados

Cisco Ios Module