First published: Tue Oct 02 2018(Updated: )
Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As of the 0.4.0 release of cisco_ios, host key checking is enabled by default.
Credit: security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Cisco Ios Module | <0.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11750 is a vulnerability in the Puppet cisco_ios module where a host's identity is not validated before starting an SSH connection.
If you are using a previous release of the Puppet cisco_ios module up to version 0.4.0, your host's identity is not validated before starting an SSH connection.
CVE-2018-11750 has a severity score of 6.5 (Medium).
To fix CVE-2018-11750, you need to upgrade to version 0.4.0 or higher of the Puppet cisco_ios module, where host key checking is enabled by default.
You can find more information about CVE-2018-11750 at the following references: [1] https://exchange.xforce.ibmcloud.com/vulnerabilities/150978 [2] https://puppet.com/security/cve/CVE-2018-11750