Show plain JSON{"id": "CVE-2018-7083", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2019-05-10T17:29:01.173", "references": [{"url": "http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-001.txt", "tags": ["Vendor Advisory"], "source": "security-alert@hpe.com"}, {"url": "http://www.securityfocus.com/bid/108374", "source": "security-alert@hpe.com"}, {"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-549547.pdf", "tags": ["Third Party Advisory"], "source": "security-alert@hpe.com"}, {"url": "http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-001.txt", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/108374", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-549547.pdf", "tags": ["Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-200"}]}], "descriptions": [{"lang": "en", "value": "If a process running within Aruba Instant crashes, it may leave behind a \"core dump\", which contains the memory contents of the process at the time it crashed. It was discovered that core dumps are stored in a way that unauthenticated users can access them through the Aruba Instant web interface. Core dumps could contain sensitive information such as keys and passwords. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0"}, {"lang": "es", "value": "Si un proceso que corre dentro de Aruba Instant se bloquea, puede conllevar a un \"volcado de memoria\", que contiene la memoria del proceso en el momento en que se bloque\u00f3. Se descubri\u00f3 que los volcados de memoria se almacenan de manera que los usuarios no autenticados puedan acceder a ellos a trav\u00e9s de la Web Interface de Aruba Instant. Los volcados de datos centrales podr\u00edan contener informaci\u00f3n sensible, como claves y contrase\u00f1as. Soluci\u00f3n alternativa: bloquee el acceso a la Web Interface de Aruba Instant de todos los usuarios que no sean de confianza. Resoluci\u00f3n: corregida en Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6 y 8.4.0.0"}], "lastModified": "2024-11-21T04:11:37.367", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:arubanetworks:aruba_instant:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC1A7F0E-2967-4FFD-AF10-993F73B29C79", "versionEndExcluding": "4.2.4.12", "versionStartIncluding": "4.0"}, {"criteria": "cpe:2.3:a:arubanetworks:aruba_instant:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C4A8C11A-80E4-4927-8794-92AED47956E7", "versionEndExcluding": "6.5.4.11", "versionStartIncluding": "6.5.0"}, {"criteria": "cpe:2.3:a:arubanetworks:aruba_instant:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3571ED0E-9E35-4B7D-80FD-DDD1FC187995", "versionEndExcluding": "8.3.0.6", "versionStartIncluding": "8.3.0"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_w1750d_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C4AB6855-E124-4F3C-9993-647B4AB1ACBF", "versionEndExcluding": "8.4.0.1"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_w1750d:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FBC30055-239F-4BB1-B2D1-E5E35F0D8911"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "security-alert@hpe.com"}