PT-2018-10806 · Puppet · Puppet Cisco Ios Module

Published

2018-10-02

·

Updated

2020-05-01

·

CVE-2018-11752

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Puppet cisco ios module versions prior to 0.4.0
Description The issue concerns the Puppet cisco ios module, which previously output SSH session debug information, including login credentials, to a world-readable file on every run.
Recommendations For versions prior to 0.4.0, update to version 0.4.0 to resolve the issue.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11752

Affected Products

Puppet Cisco Ios Module