Improper access control in SAGA1-L - CVE-2018-20783
Published: October 24, 2018
Vulnerability identifier: #VU15509
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20783
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an adjacent attacker to bypass authentication on the target system.
The vulnerability exists due to improper access control. An adjacent attacker can force-pair the device without human interaction.
Affected software
SAGA1-L
Red Hat Software Collections
php7 (Alpine package)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Opensuse
Red Hat Software Collections
php7 (Alpine package)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Opensuse
How to mitigate CVE-2018-20783
Update to version A0.10.
SAGA1-L - update to
php7 (Alpine package) - addressed in versions 7.1.30-r0, 7.2.17-r0
php7 (Alpine package) - addressed in versions 7.1.30-r0, 7.2.17-r0