CVE-2018-0040: Contrail Service Orchestration: hardcoded cryptographic certificates and keys
Published Jul 11, 2018
·Updated
Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services.
Affected Software
1 affected component
Juniper Contrail Service Orchestration<4.0.0
Remediation
Information
This issue is fixed in Contrail Service Orchestration 4.0.0 and subsequent releases.
Event History
Jul 11, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0040?
CVE-2018-0040 has been assigned a high severity rating due to the risk of unauthorized access it introduces.
2
How do I fix CVE-2018-0040?
To remediate CVE-2018-0040, upgrade to Juniper Networks Contrail Service Orchestrator version 4.0.0 or later.
3
What causes CVE-2018-0040?
CVE-2018-0040 is caused by the use of hardcoded cryptographic certificates and keys in affected software versions.
4
Which versions of Juniper Contrail Service Orchestrator are affected by CVE-2018-0040?
CVE-2018-0040 affects all versions of Juniper Contrail Service Orchestrator prior to 4.0.0.
5
What type of attackers can exploit CVE-2018-0040?
Network-based attackers can exploit CVE-2018-0040 to gain unauthorized access to services.