CVE-2018-0008
published 2018-01-10CVE-2018-0008: An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain instructions…
PriorityP427medium6.2CVSS 3.0
AVPACLPRHUINSUCHIHAH
EPSS
0.45%
36.5th percentile
An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain instructions during commit, which is configured under the [system scripts commit] stanza. Certain commit scripts that work without a problem during normal commit may cause unexpected behavior upon reboot which can leave the system in a state where root CLI login is allowed without a password due to the system reverting to a "safe mode" authentication state. Lastly, only logging in physically to the console port as root, with no password, will work. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D71 on SRX; 12.3X48 versions prior to 12.3X48-D55 on SRX; 14.1 versions prior to 14.1R9; 14.1X53 versions prior to 14.1X53-D40 on QFX, EX; 14.2 versions prior to 14.2R7-S9, 14.2R8; 15.1 versions prior to 15.1F5-S7, 15.1F6-S8, 15.1R5-S6, 15.1R6; 15.1X49 versions prior to 15.1X49-D110 on SRX; 15.1X53 versions prior to 15.1X53-D232 on QFX5200/5110; 15.1X53 versions prior to 15.1X53-D49, 15.1X53-D470 on NFX; 15.1X53 versions prior to 15.1X53-D65 on QFX10K; 16.1 versions prior to 16.1R2. No other Juniper Networks products or platforms are affected by this issue.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper | qfx_series | — | — |
| juniper | srx_series | — | — |
| juniper_networks | junos_os | >= 12.1X46 < 12.1X46-D71 | 12.1X46-D71 |
| juniper_networks | junos_os | >= 12.3X48 < 12.3X48-D55 | 12.3X48-D55 |
| juniper_networks | junos_os | >= 14.1 < 14.1R9 | 14.1R9 |
| juniper_networks | junos_os | >= 14.1X53 < 14.1X53-D40 | 14.1X53-D40 |
| juniper_networks | junos_os | >= 14.2 < 14.2R7-S9, 14.2R8 | 14.2R7-S9, 14.2R8 |
| juniper_networks | junos_os | >= 15.1 < 15.1F5-S7, 15.1F6-S8, 15.1R5-S6, 15.1R6 | 15.1F5-S7, 15.1F6-S8, 15.1R5-S6, 15.1R6 |
| juniper_networks | junos_os | >= 15.1X49 < 15.1X49-D110 | 15.1X49-D110 |
| juniper_networks | junos_os | >= 15.1X53 < 15.1X53-D232 | 15.1X53-D232 |
| juniper_networks | junos_os | >= 15.1X53 < 15.1X53-D49, 15.1X53-D470 | 15.1X53-D49, 15.1X53-D470 |
| juniper_networks | junos_os | >= 15.1X53 < 15.1X53-D65 | 15.1X53-D65 |
| juniper_networks | junos_os | >= 16.1 < 16.1R2 | 16.1R2 |
CVSS provenance
nvdv3.06.2MEDIUMCVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-95c8-g3xm-ffh5: An unauthenticated root login may allow upon reboot when a commit script is used
ghsa_unreviewed·2022-05-13
CVE-2018-0008 [HIGH] CWE-287 GHSA-95c8-g3xm-ffh5: An unauthenticated root login may allow upon reboot when a commit script is used
An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain instructions during commit, which is configured under the [system scripts commit] stanza. Certain commit scripts that work without a problem during normal commit may cause unexpected behavior upon reboot which can leave the system in a state where root CLI login is allowed without a password due to the system reverting to a "safe mode" authentication state. Lastly, only logging in physically to the console port as root, with no password, will work. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D71 on SRX; 12.3X48 versions prior to 12.3X48-D55 on SRX; 14.1 versions prior to 14.1R9; 14.1X53 versions prior to 14
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
VMware
VMware product updates enable Hypervisor-Specific Mitigations, Hypervisor-Assisted Guest Mitigations, and Operating System-Specific Mitigations for Microarchitectural Data Sampling (MDS) Vulnerabiliti
vendor_vmware·2019-05-14·CVSS 5.6
CVE-2018-12126 [MEDIUM] VMware product updates enable Hypervisor-Specific Mitigations, Hypervisor-Assisted Guest Mitigations, and Operating System-Specific Mitigations for Microarchitectural Data Sampling (MDS) Vulnerabiliti
VMSA-2019-0008: VMware product updates enable Hypervisor-Specific Mitigations, Hypervisor-Assisted Guest Mitigations, and Operating System-Specific Mitigations for Microarchitectural Data Sampling (MDS) Vulnerabilities (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, and CVE-2019-11091)
| Advisory Severity | Moderate | CVSSv3 Range | 3.8 - 6.5 | Synopsis | VMware product updates enable Hypervisor-Specific Mitigations, Hypervisor-Assisted Guest Mitigations, and Operating System-Specific Mitigations for Microarchitectural Data Sampling (MDS) Vulnerabilities (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, and CVE-2019-11091) | Issue Date | 2019-05-14 | Updated On | 2019-11-12 | CVE(s) | CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, and CVE-2019-11091 VMware vCenter Server (VC) VMware vSph
VMware
Workstation and Fusion updates address a denial-of-service vulnerability
vendor_vmware·2018-03-15·CVSS 5.3
CVE-2018-6957 [MEDIUM] Workstation and Fusion updates address a denial-of-service vulnerability
VMSA-2018-0008: Workstation and Fusion updates address a denial-of-service vulnerability
Workstation and Fusion updates address a denial-of-service vulnerability 2. Relevant Products VMware Workstation Pro / Player (Workstation) VMware Fusion Pro / Fusion (Fusion) 3. Problem Description Denial-of-service vulnerability through VNC VMware Workstation and Fusion contain a denial-of-service vulnerability which can be triggered by opening a large number of VNC sessions. Note: In order for exploitation to be possible on Workstation and Fusion, VNC must be manually enabled. VMware would like to thank Lilith Wyatt of Cisco Talos for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2018-6957 to this issue. Column 5 of the
Juniper
CVE-2018-0008: An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain ins
vendor_juniper·2018-01-10·CVSS 6.2
CVE-2018-0008 [MEDIUM] CWE-287 CVE-2018-0008: An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain ins
CVE-2018-0008: An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain instructions during commit, which is configured under the [system scripts commit] stanza. Certain commit scripts that work without a problem during normal commit may cause unexpected behavior upon reboot which can leave the system in a state where root CLI login is allowed without a password due to the system reverting to a "safe mode" authentication state. Lastly, only logging in physically to the console port as root, with no password, will work. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D71 on SRX; 12.3X48 versions prior to 12.3X48-D55 on SRX; 14.1 versions prior to 14.1R9; 14.1X53 versi
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-18625 grafana: XSS vulnerability via a link on the "Dashboard > All Panels > General" screen
bugzilla·2020-06-24·CVSS 6.1
CVE-2018-18625 [MEDIUM] CVE-2018-18625 grafana: XSS vulnerability via a link on the "Dashboard > All Panels > General" screen
CVE-2018-18625 grafana: XSS vulnerability via a link on the "Dashboard > All Panels > General" screen
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
https://github.com/grafana/grafana/pull/11813
https://security.netapp.com/advisory/ntap-20200608-0008/
Discussion:
Created grafana tracking bugs for this issue:
Affects: fedora-all [bug 1850584]
---
This vulnerability actually applies to the "dashboard" field at "Home > Edit Panel > Add Link > General > Dashboard" after the dashboard title has been set: https://github.com/grafana/grafana/pull/11813#issuecomment-458000030
---
OpenShift packages a vulnerable version of grafana:
- OpenShift 3.11 grafana v5.2.3
ServiceMesh also pa
Bugzilla
CVE-2018-18624 grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen
bugzilla·2020-06-24·CVSS 6.1
CVE-2018-18624 [MEDIUM] CVE-2018-18624 grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen
CVE-2018-18624 grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen
Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
https://github.com/grafana/grafana/pull/11813
https://security.netapp.com/advisory/ntap-20200608-0008/
Discussion:
Created grafana tracking bugs for this issue:
Affects: fedora-all [bug 1850573]
---
Upstream commit: https://github.com/grafana/grafana/commit/0284747c88eb9435899006d26ffaf65f89dec88e
---
ServiceMesh packages a vulnerable version of grafana v6.4.3 in the openshift-service-mesh/grafana-rhel8 container.
---
upstream PR: https://github.com/grafana/grafana/pull/23816
---
Statement:
Both OpenShift 3.11 and 4.x grafan
Bugzilla
CVE-2018-18623 grafana: XSS vulnerability via the "Dashboard > Text Panel" screen
bugzilla·2020-06-24·CVSS 6.1
CVE-2018-18623 [MEDIUM] CVE-2018-18623 grafana: XSS vulnerability via the "Dashboard > Text Panel" screen
CVE-2018-18623 grafana: XSS vulnerability via the "Dashboard > Text Panel" screen
Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
https://github.com/grafana/grafana/pull/11813
https://security.netapp.com/advisory/ntap-20200608-0008/
Discussion:
Created grafana tracking bugs for this issue:
Affects: fedora-all [bug 1850570]
---
Upstream commit: https://github.com/grafana/grafana/pull/14984/commits/15d560a1c01f5bfb354f83183886881554026bb8
Looks like that is the patch given the comment: https://github.com/grafana/grafana/pull/11813#issuecomment-458045266
The patch got included in the major release of v6.0.0 as well.
---
OpenShift 3.11 grafana-container packages a vulnerable version of grafana 5.
Bugzilla
CVE-2018-1133 CVE-2018-1134 CVE-2018-1135 CVE-2018-1136 CVE-2018-1137 moodle: Six security issues fixed in the latest release
bugzilla·2018-05-25·CVSS 8.8
CVE-2018-1133 [HIGH] CVE-2018-1133 CVE-2018-1134 CVE-2018-1135 CVE-2018-1136 CVE-2018-1137 moodle: Six security issues fixed in the latest release
CVE-2018-1133 CVE-2018-1134 CVE-2018-1135 CVE-2018-1136 CVE-2018-1137 moodle: Six security issues fixed in the latest release
MSA-18-0007: Calculated question type allows remote code execution by Question authors - CVE-2018-1133
Teacher creating Calculated question can intentionally cause remote code execution on server
https://moodle.org/mod/forum/discuss.php?d=371199
MSA-18-0008: Users can download any file via portfolio assignment caller class - CVE-2018-1134
Students who submitted assignments and exported it to portfolios can download any stored Moodle file by changing download URL
https://moodle.org/mod/forum/discuss.php?d=371200
MSA-18-0009: Portfolio forum caller class allows a user to download any file - CVE-2018-1135
Students who posted on forum and exported the post to po
http://www.securitytracker.com/id/1040186https://kb.juniper.net/JSA10835https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttp://www.securitytracker.com/id/1040186https://kb.juniper.net/JSA10835https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3E
2018-01-10
Published