Improper authentication in Policy Suite - CVE-2018-0181
Published: January 10, 2019
Vulnerability identifier: #VU16902
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0181
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists in the Redis implementation due to improper authentication when accessing the Redis server. A remote attacker can modify key-value pairs stored within the Redis server database and reduce the efficiency of the software.
Affected software
Policy Suite
Policy Suite Diameter Routing Agent
Policy Suite Diameter Routing Agent
How to mitigate CVE-2018-0181
Update to version 18.3.0.
Policy Suite - update to 18.3.0