8.8
CVE-2018-5413
- EPSS 0.36%
- Veröffentlicht 10.01.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:46
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilege escalation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imperva ≫ Securesphere Version11.5
Imperva ≫ Securesphere Version12.0
Imperva ≫ Securesphere Version13.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.57 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-250 Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.