Vulnerability Name: | CVE-2018-4300 (CCN-148370) | ||||||||||||||||||
Assigned: | 2018-08-14 | ||||||||||||||||||
Published: | 2018-08-14 | ||||||||||||||||||
Updated: | 2019-09-28 | ||||||||||||||||||
Summary: | The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10. | ||||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
6.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.4 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||
Vulnerability Type: | CWE-200 CWE-330 | ||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-4300 Source: CCN Type: BugTraq Mailing List, Tue, 14 Aug 2018 15:46:17 +0200 X41 D-Sec GmbH Security Advisory X41-2018-005: Multiple Vulnerabilities in Apple smartcardservices Source: BID Type: Third Party Advisory 107785 Source: XF Type: UNKNOWN smartcardservices-cve20184300-bo(148370) Source: MISC Type: Release Notes, Third Party Advisory https://github.com/apple/cups/releases/tag/v2.2.10 Source: MLIST Type: UNKNOWN [debian-lts-announce] 20190928 [SECURITY] [DLA 1936-1] cups security update Source: CCN Type: smartcardservices SCSSU-201801 Security Updates | ||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Denotes that component is vulnerable | ||||||||||||||||||
Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
BACK |