SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1129

An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol.

MEDIUM 6.5EPSS 1.90%

Does this matter?

Lower severity and a low EPSS score (1.90%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
1.90% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-284, CWE-287
Affected
redhat/ceph storage · redhat/ceph storage mon · redhat/ceph storage osd · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · ceph/ceph · debian/debian linux · opensuse/leap
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.