CVE-2018-3775Improper Authentication in Server

Severity
8.8HIGHNVD
EPSS
0.2%
top 57.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateMay 13

Description

Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-2v55-qcx6-c482: Improper Authentication in Nextcloud Server prior to version 122022-05-13
CVEList
CVE-2018-3775: Improper Authentication in Nextcloud Server prior to version 122018-08-12

💬Community

3
Bugzilla
CVE-2018-3775 nextcloud: Improper authentication allows attackers with user credentials to bypass 2FA2018-08-22
Bugzilla
CVE-2018-3775 nextcloud: Improper authentication allows attackers with user credentials to bypass 2FA [epel-7]2018-08-22
Bugzilla
CVE-2018-3775 nextcloud: Improper authentication allows attackers with user credentials to bypass 2FA [fedora-all]2018-08-22
CVE-2018-3775 — Improper Authentication in Server | cvebase