First published: Mon Sep 09 2019(Updated: )
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive nature and are not expected to be publicly accessible.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Librenms Librenms | <=1.47 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-10668.
The severity of CVE-2019-10668 is critical with a CVSS score of 9.1.
The affected software is LibreNMS version up to and including 1.47.
This vulnerability allows an attacker to bypass authentication and access sensitive information or functions that should not be publicly accessible.
Yes, a fix is available for CVE-2019-10668. It is recommended to update to a version beyond 1.47.