CVE-2018-1800
published 2018-09-20CVE-2018-1800: IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive information during a short time period…
PriorityP418medium4.7CVSS 3.0
AVLACHPRLUINSUCHINAN
EPSS
0.30%
21.6th percentile
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive information during a short time period when installation is occurring. IBM X-Force ID: 149607.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sterling_b2b_integrator | — | — |
| ibm | sterling_b2b_integrator | — | — |
| ibm | sterling_b2b_integrator | — | — |
| ibm | sterling_b2b_integrator | 5.2.6.0 – 5.2.6.3 | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vmhf-hhxg-4fr5: IBM Sterling B2B Integrator Standard Edition 5
ghsa_unreviewed·2022-05-13
CVE-2018-1800 [MEDIUM] CWE-200 GHSA-vmhf-hhxg-4fr5: IBM Sterling B2B Integrator Standard Edition 5
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive information during a short time period when installation is occurring. IBM X-Force ID: 149607.
Cisco
Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
vendor_cisco·2018-10-17·CVSS 5.8
CVE-2018-0381 [MEDIUM] CWE-667 Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
A vulnerability in the Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
The vulnerability is due to a deadlock condition that may occur when an affected AP attempts to dequeue aggregated traffic that is destined to an attacker-controlled wireless client. An attacker who can successfully transition between multiple Service Set Identifiers (SSIDs) hosted on the same AP while replicating the required traffic patterns could trigger the deadlock condition. A watchdog timer that detects the condition will trigger a reload of th
Cisco
Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
vendor_cisco·2018-05-02·CVSS 7.5
CVE-2018-0226 [HIGH] CWE-255 Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running Cisco Mobility Express Software could allow an authenticated, remote attacker to gain elevated privileges on an affected access point.
The vulnerability exists because the Cisco Mobility Express controller of the affected software configures the default SSH user account for an access point to be the first SSH user account that was created for the Mobility Express controller, if an administrator added user accounts directly to the controller instead of using the default configuration or the SSH username creatio
Cisco
Cisco Aironet 1800 Series Access Point 802.11 Denial of Service Vulnerability
vendor_cisco·2018-05-02·CVSS 4.7
CVE-2018-0249 [MEDIUM] CWE-20 Cisco Aironet 1800 Series Access Point 802.11 Denial of Service Vulnerability
Cisco Aironet 1800 Series Access Point 802.11 Denial of Service Vulnerability
A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Qualcomm Atheros (QCA) based hardware platforms could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. A successful exploit could prevent new clients from joining the AP.
The vulnerability is due to incorrect handling of malformed or invalid 802.11 Association Requests. An attacker could exploit this vulnerability by sending a malformed stream of 802.11 Association Requests to the local interface of the targeted device. A successful exploit could allow the attacker to cause a DoS situation on an affected system, causing new client 8
Cisco
Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0226 Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
CVE-2018-0226: Cisco Aironet 1800, 2800, and 3800 Series Access Points Secure Shell Privilege Escalation Vulnerability
A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running Cisco Mobility Express Software could allow an authenticated, remote attacker to gain elevated privileges on an affected access point. The vulnerability exists because the Cisco Mobility Express controller of the affected software configures the default SSH user account for an access point to be the first SSH user account that was created for the Mobility Express controller, if an administrator added user accounts directly to the controller instead of using the default configuration or the SSH us
Cisco
Cisco Aironet 1800 Series Access Point 802.11 Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0249 Cisco Aironet 1800 Series Access Point 802.11 Denial of Service Vulnerability
CVE-2018-0249: Cisco Aironet 1800 Series Access Point 802.11 Denial of Service Vulnerability
A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Qualcomm Atheros (QCA) based hardware platforms could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. A successful exploit could prevent new clients from joining the AP. The vulnerability is due to incorrect handling of malformed or invalid 802.11 Association Requests. An attacker could exploit this vulnerability by sending a malformed stream of 802.11 Association Requests to the local interface of the targeted device. A successful exploit could allow the attacker to cause a DoS situation on an affected system, causing
Cisco
Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0381 Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
CVE-2018-0381: Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points Denial of Service Vulnerability
A vulnerability in the Cisco Aironet 1560, 1800, 2800, and 3800 Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a deadlock condition that may occur when an affected AP attempts to dequeue aggregated traffic that is destined to an attacker-controlled wireless client. An attacker who can successfully transition between multiple Service Set Identifiers (SSIDs) hosted on the same AP while replicating the required traffic patterns could trigger the deadlock condition. A watchdog timer that detects the condition will trigger
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-09-20
Published