Improper access control in SAGA1-L - CVE-2018-20783

 

Improper access control in SAGA1-L - CVE-2018-20783

Published: October 24, 2018


Vulnerability identifier: #VU15509
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20783
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to bypass authentication on the target system.

The vulnerability exists due to improper access control. An adjacent attacker can force-pair the device without human interaction.


Affected software

SAGA1-L
Red Hat Software Collections
php7 (Alpine package)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Opensuse

How to mitigate CVE-2018-20783

Update to version A0.10.

SAGA1-L - update to
php7 (Alpine package) - addressed in versions 7.1.30-r0, 7.2.17-r0

External References

Related Security Bulletins