PT-2018-17619 · Icinga · Icinga

Crunsher

·

Published

2018-02-27

·

Updated

2019-10-03

·

CVE-2018-6535

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Icinga versions 2.x through 2.8.1
Description An issue in the password comparison function can disclose the password to an attacker due to the lack of a constant-time comparison, potentially allowing attackers to exploit this and gain unauthorized access.
Recommendations For versions 2.x through 2.8.1, update to a version that includes a constant-time password comparison function to prevent password disclosure.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-6535

Affected Products

Icinga