CVE-2019-10668: Critical severity librenms vulnerability
Published Sep 9, 2019
·Updated
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive nature and are not expected to be publicly accessible.
Affected Software
1 affected component
librenms librenms<=1.47
Event History
Sep 9, 2019
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-10668.
2
What is the severity of CVE-2019-10668?
The severity of CVE-2019-10668 is critical with a CVSS score of 9.1.
3
What is the affected software?
The affected software is LibreNMS version up to and including 1.47.
4
What does this vulnerability allow an attacker to do?
This vulnerability allows an attacker to bypass authentication and access sensitive information or functions that should not be publicly accessible.
5
Is there a fix available for CVE-2019-10668?
Yes, a fix is available for CVE-2019-10668. It is recommended to update to a version beyond 1.47.