// For flags

CVE-2018-7083

 

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time it crashed. It was discovered that core dumps are stored in a way that unauthenticated users can access them through the Aruba Instant web interface. Core dumps could contain sensitive information such as keys and passwords. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0

Si un proceso que corre dentro de Aruba Instant se bloquea, puede conllevar a un "volcado de memoria", que contiene la memoria del proceso en el momento en que se bloqueó. Se descubrió que los volcados de memoria se almacenan de manera que los usuarios no autenticados puedan acceder a ellos a través de la Web Interface de Aruba Instant. Los volcados de datos centrales podrían contener información sensible, como claves y contraseñas. Solución alternativa: bloquee el acceso a la Web Interface de Aruba Instant de todos los usuarios que no sean de confianza. Resolución: corregida en Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6 y 8.4.0.0

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-02-15 CVE Reserved
  • 2019-05-10 CVE Published
  • 2024-05-03 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Scalance W1750d Firmware
Search vendor "Siemens" for product "Scalance W1750d Firmware"
< 8.4.0.1
Search vendor "Siemens" for product "Scalance W1750d Firmware" and version " < 8.4.0.1"
-
Affected
in Siemens
Search vendor "Siemens"
Scalance W1750d
Search vendor "Siemens" for product "Scalance W1750d"
--
Safe
Arubanetworks
Search vendor "Arubanetworks"
Aruba Instant
Search vendor "Arubanetworks" for product "Aruba Instant"
>= 4.0 < 4.2.4.12
Search vendor "Arubanetworks" for product "Aruba Instant" and version " >= 4.0 < 4.2.4.12"
-
Affected
Arubanetworks
Search vendor "Arubanetworks"
Aruba Instant
Search vendor "Arubanetworks" for product "Aruba Instant"
>= 6.5.0 < 6.5.4.11
Search vendor "Arubanetworks" for product "Aruba Instant" and version " >= 6.5.0 < 6.5.4.11"
-
Affected
Arubanetworks
Search vendor "Arubanetworks"
Aruba Instant
Search vendor "Arubanetworks" for product "Aruba Instant"
>= 8.3.0 < 8.3.0.6
Search vendor "Arubanetworks" for product "Aruba Instant" and version " >= 8.3.0 < 8.3.0.6"
-
Affected