CVE-2018-11045: Medium severity Pivotal Software Operations Manager vulnerability
Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could get the contents of the corresponding seed from the published image and therefore infer the initial state of the LRNG.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11045?
CVE-2018-11045 is a vulnerability in Pivotal Operations Manager versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22.
What is the severity of CVE-2018-11045?
CVE-2018-11045 has a severity level of medium with a severity score of 5.9.
How does CVE-2018-11045 affect Pivotal Operations Manager?
CVE-2018-11045 affects Pivotal Operations Manager versions 2.1 prior to 2.1.6, 2.0 prior to 2.0.15, and 1.12 prior to 1.12.22 by containing a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image.
How can an attacker exploit CVE-2018-11045?
An attacker with knowledge of the exact version and IaaS of a running OpsManager could exploit CVE-2018-11045 to obtain the LRNG seed file, potentially compromising cryptographic keys used by the system.
Is there a fix for CVE-2018-11045?
Yes, updating to Pivotal Operations Manager versions 2.1.6, 2.0.15, and 1.12.22 or later will resolve the vulnerability.