CVE-2018-11752: Medium severity puppet cisco ios vulnerability
Published Oct 2, 2018
·Updated
Previous releases of the Puppet ciscoios module output SSH session debug information including login credentials to a world readable file on every run. These issues have been resolved in the 0.4.0 release.
Affected Software
1 affected component
Puppet Cisco Ios Puppet<0.4.0
Event History
Oct 2, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11752?
The severity of CVE-2018-11752 is medium with a severity value of 5.5.
2
What is the affected software for CVE-2018-11752?
The affected software for CVE-2018-11752 is Puppet Cisco Ios versions up to (but not including) 0.4.0.
3
How can I fix CVE-2018-11752?
To fix CVE-2018-11752, you should update to version 0.4.0 of Puppet Cisco Ios module.
4
What is the Common Weakness Enumeration (CWE) for CVE-2018-11752?
The Common Weakness Enumeration (CWE) for CVE-2018-11752 is CWE-522.
5
Where can I find more information about CVE-2018-11752?
You can find more information about CVE-2018-11752 on the Puppet Security Advisory page: https://puppet.com/security/cve/CVE-2018-11752