CVE-2018-7083 — Sensitive Information Exposure in Aruba Instant
Severity
7.5HIGHNVD
EPSS
0.4%
top 38.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 10
Latest updateMay 24
Description
If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time it crashed. It was discovered that core dumps are stored in a way that unauthenticated users can access them through the Aruba Instant web interface. Core dumps could contain sensitive information such as keys and passwords. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.…
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-6cm4-h3cj-qjv6: If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time it↗2022-05-24
CVEList▶
CVE-2018-7083: If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time it↗2019-05-10