Lucene search

K
cveHackeroneCVE-2018-16499
HistoryMay 26, 2021 - 7:15 p.m.

CVE-2018-16499

2021-05-2619:15:08
CWE-326
hackerone
web.nvd.nist.gov
18
vos
compromise
man-in-the-middle attacks
ssh encryption protocols
cipher suites
data protection tsr
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

35.0%

In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unapproved SSH encryption protocols or cipher suites also violates the Data Protection TSR (Technical Security Requirements).

Affected configurations

Nvd
Vulners
Node
versa-networksversa_operating_systemMatch-
VendorProductVersionCPE
versa-networksversa_operating_system-cpe:2.3:o:versa-networks:versa_operating_system:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Versa VOS",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed Versions: 16.1R2S11, 20.2.2, 21.1.1, 21.2.1"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

35.0%

Related for CVE-2018-16499