CVE-2018-19878: Use After Free
An issue was discovered on Teltonika RTU950 R31.04.89 devices. The application allows a user to login without limitation. For every successful login request, the application saves a session. A user can re-login without logging out, causing the application to store the session in memory. Exploitation of this vulnerability will increase memory use and consume free space.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19878?
CVE-2018-19878 is considered a high-severity vulnerability due to its impact on user session management.
How do I fix CVE-2018-19878?
To mitigate CVE-2018-19878, ensure that the firmware is updated to the latest version provided by Teltonika that addresses this vulnerability.
Who is affected by CVE-2018-19878?
CVE-2018-19878 affects users of the Teltonika RUT950 devices running firmware version R_31.04.89.
What is the nature of the vulnerability in CVE-2018-19878?
The vulnerability in CVE-2018-19878 allows multiple concurrent logins, leading to session management issues and potential unauthorized access.
Can CVE-2018-19878 be exploited remotely?
Yes, CVE-2018-19878 can be exploited remotely, making it critical for users to secure their devices.