CVE-2018-7083
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time it crashed. It was discovered that core dumps are stored in a way that unauthenticated users can access them through the Aruba Instant web interface. Core dumps could contain sensitive information such as keys and passwords. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0
Si un proceso que corre dentro de Aruba Instant se bloquea, puede conllevar a un "volcado de memoria", que contiene la memoria del proceso en el momento en que se bloqueó. Se descubrió que los volcados de memoria se almacenan de manera que los usuarios no autenticados puedan acceder a ellos a través de la Web Interface de Aruba Instant. Los volcados de datos centrales podrían contener información sensible, como claves y contraseñas. Solución alternativa: bloquee el acceso a la Web Interface de Aruba Instant de todos los usuarios que no sean de confianza. Resolución: corregida en Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6 y 8.4.0.0
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-15 CVE Reserved
- 2019-05-10 CVE Published
- 2024-05-03 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/108374 | Vdb Entry | |
https://cert-portal.siemens.com/productcert/pdf/ssa-549547.pdf | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-001.txt | 2019-05-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Scalance W1750d Firmware Search vendor "Siemens" for product "Scalance W1750d Firmware" | < 8.4.0.1 Search vendor "Siemens" for product "Scalance W1750d Firmware" and version " < 8.4.0.1" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance W1750d Search vendor "Siemens" for product "Scalance W1750d" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Aruba Instant Search vendor "Arubanetworks" for product "Aruba Instant" | >= 4.0 < 4.2.4.12 Search vendor "Arubanetworks" for product "Aruba Instant" and version " >= 4.0 < 4.2.4.12" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Aruba Instant Search vendor "Arubanetworks" for product "Aruba Instant" | >= 6.5.0 < 6.5.4.11 Search vendor "Arubanetworks" for product "Aruba Instant" and version " >= 6.5.0 < 6.5.4.11" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Aruba Instant Search vendor "Arubanetworks" for product "Aruba Instant" | >= 8.3.0 < 8.3.0.6 Search vendor "Arubanetworks" for product "Aruba Instant" and version " >= 8.3.0 < 8.3.0.6" | - |
Affected
|