CVE-2018-1000500Improper Certificate Validation in Busybox

Severity
8.1HIGHNVD
EPSS
0.6%
top 31.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26
Latest updateMay 13

Description

Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-248x-4c3j-hcg7: Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution2022-05-13
OSV
CVE-2018-1000500: Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution2018-06-26

📋Vendor Advisories

4
Ubuntu
BusyBox vulnerability2020-09-22
Microsoft
Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download a2018-06-12
Red Hat
busybox: wget: Missing SSL certificate validation2018-05-24
Debian
CVE-2018-1000500: busybox - Busybox contains a Missing SSL certificate validation vulnerability in The "busy...2018

💬Community

3
Bugzilla
CVE-2018-1000500 busybox: wget: Missing SSL certificate validation2018-06-27
Bugzilla
CVE-2018-1000500 busybox: wget: Missing SSL certificate validation [fedora-all]2018-06-27
Bugzilla
CVE-2018-1000500 wget: Missing SSL certificate validation [fedora-all]2018-06-27