CVE-2018-6695: Threat Intelligence Exchange Server (TIE Server) SSH host keys generation vulnerability
SSH host keys generation vulnerability in the server in McAfee Threat Intelligence Exchange Server (TIE Server) 1.3.0, 2.0.x, 2.1.x, 2.2.0 allows man-in-the-middle attackers to spoof servers via acquiring keys from another environment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6695?
CVE-2018-6695 has a high severity rating as it allows man-in-the-middle attacks that can lead to server spoofing.
How do I fix CVE-2018-6695?
To fix CVE-2018-6695, upgrade to the patched version of McAfee Threat Intelligence Exchange Server, which is not affected by this vulnerability.
Which versions of McAfee Threat Intelligence Exchange Server are affected by CVE-2018-6695?
CVE-2018-6695 affects McAfee Threat Intelligence Exchange Server versions 1.3.0, 2.0.x, 2.1.x, and 2.2.0.
What types of attacks can CVE-2018-6695 facilitate?
CVE-2018-6695 can facilitate man-in-the-middle attacks that allow attackers to spoof trusted server communications.
Is there a workaround for CVE-2018-6695?
There is no documented workaround for CVE-2018-6695; the recommended action is to update to a secure version.