SB2019011005 - Authentication bypass in Cisco Policy Suite Diameter Routing Agent
Published: January 10, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper authentication (CVE-ID: CVE-2018-0181)
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists in the Redis implementation due to improper authentication when accessing the Redis server. A remote attacker can modify key-value pairs stored within the Redis server database and reduce the efficiency of the software.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.