CVE-2018-11750: Input Validation
Previous releases of the Puppet ciscoios module did not validate a host's identity before starting a SSH connection. As of the 0.4.0 release of ciscoios, host key checking is enabled by default.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11750?
CVE-2018-11750 is a vulnerability in the Puppet cisco_ios module where a host's identity is not validated before starting an SSH connection.
How does CVE-2018-11750 affect me?
If you are using a previous release of the Puppet cisco_ios module up to version 0.4.0, your host's identity is not validated before starting an SSH connection.
What is the severity of CVE-2018-11750?
CVE-2018-11750 has a severity score of 6.5 (Medium).
How can I fix CVE-2018-11750?
To fix CVE-2018-11750, you need to upgrade to version 0.4.0 or higher of the Puppet cisco_ios module, where host key checking is enabled by default.
Where can I find more information about CVE-2018-11750?
You can find more information about CVE-2018-11750 at the following references: [1] https://exchange.xforce.ibmcloud.com/vulnerabilities/150978 [2] https://puppet.com/security/cve/CVE-2018-11750