PT-2018-10805 · Puppet · Cisco Ios Module
Published
2018-10-02
·
Updated
2019-01-02
·
CVE-2018-11750
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Puppet cisco ios module versions prior to 0.4.0
Description
The issue concerns the lack of host identity validation before establishing a SSH connection. This has been addressed in the 0.4.0 release of the cisco ios module, where host key checking is enabled by default.
Recommendations
For versions prior to 0.4.0, update to version 0.4.0 or later to enable host key checking by default.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Module