ID

VAR-201902-0502


CVE

CVE-2018-15778


TITLE

Dell OS10 Input validation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-014431

DESCRIPTION

Dell OS10 versions prior to 10.4.2.1 contain a vulnerability caused by lack of proper input validation on the command-line interface (CLI). Dell OS10 Contains an input validation vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Dell Networking OS10 is prone to a remote arbitrary command-execution vulnerability because it fails to sanitize user-supplied input. A local attacker can exploit this issue to execute arbitrary commands with root privileges. Dell OS10 versions prior to 10.4.2.1 are vulnerable. Dell OS10 is a Linux-based network switch operating system developed by Dell

Trust: 1.98

sources: NVD: CVE-2018-15778 // JVNDB: JVNDB-2018-014431 // BID: 107206 // VULHUB: VHN-126071

AFFECTED PRODUCTS

vendor:dellmodel:networking os10scope:ltversion:10.4.2.1

Trust: 1.8

vendor:dellmodel:networking os10scope:eqversion:10.4.2.0

Trust: 0.3

vendor:dellmodel:networking os10scope:eqversion:10.4.1.0

Trust: 0.3

vendor:dellmodel:networking os10scope:eqversion:10.4.0

Trust: 0.3

vendor:dellmodel:networking os10scope:neversion:10.4.2.1

Trust: 0.3

vendor:dellmodel:networking os10scope:neversion:10.4.1.4

Trust: 0.3

vendor:dellmodel:networking os10 10.4.0-r3sscope:neversion: -

Trust: 0.3

sources: BID: 107206 // JVNDB: JVNDB-2018-014431 // NVD: CVE-2018-15778

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-15778
value: HIGH

Trust: 1.0

security_alert@emc.com: CVE-2018-15778
value: HIGH

Trust: 1.0

NVD: CVE-2018-15778
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201902-048
value: MEDIUM

Trust: 0.6

VULHUB: VHN-126071
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-15778
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-126071
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-15778
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

security_alert@emc.com: CVE-2018-15778
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.0
impactScore: 6.0
version: 3.0

Trust: 1.0

sources: VULHUB: VHN-126071 // JVNDB: JVNDB-2018-014431 // CNNVD: CNNVD-201902-048 // NVD: CVE-2018-15778 // NVD: CVE-2018-15778

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-126071 // JVNDB: JVNDB-2018-014431 // NVD: CVE-2018-15778

THREAT TYPE

local

Trust: 0.3

sources: BID: 107206

TYPE

command injection

Trust: 0.6

sources: CNNVD: CNNVD-201902-048

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-014431

PATCH

title:Dell Networking OS10 OS Command Injection Vulnerabilityurl:https://www.dell.com/support/article/sln316095/

Trust: 0.8

sources: JVNDB: JVNDB-2018-014431

EXTERNAL IDS

db:NVDid:CVE-2018-15778

Trust: 2.8

db:JVNDBid:JVNDB-2018-014431

Trust: 0.8

db:CNNVDid:CNNVD-201902-048

Trust: 0.7

db:BIDid:107206

Trust: 0.3

db:VULHUBid:VHN-126071

Trust: 0.1

sources: VULHUB: VHN-126071 // BID: 107206 // JVNDB: JVNDB-2018-014431 // CNNVD: CNNVD-201902-048 // NVD: CVE-2018-15778

REFERENCES

url:https://www.dell.com/support/article/sln316095/

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-15778

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-15778

Trust: 0.8

url:http://en.community.dell.com/techcenter/systems-management/w/wiki/4357.idrac6-home.aspx

Trust: 0.3

url:http://en.community.dell.com/techcenter/extras/m/white_papers/20441859

Trust: 0.3

sources: VULHUB: VHN-126071 // BID: 107206 // JVNDB: JVNDB-2018-014431 // CNNVD: CNNVD-201902-048 // NVD: CVE-2018-15778

CREDITS

Thorsten Tüllmann from the Karlsruhe Institute of Technology

Trust: 0.3

sources: BID: 107206

SOURCES

db:VULHUBid:VHN-126071
db:BIDid:107206
db:JVNDBid:JVNDB-2018-014431
db:CNNVDid:CNNVD-201902-048
db:NVDid:CVE-2018-15778

LAST UPDATE DATE

2024-11-23T23:04:53.688000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-126071date:2019-10-09T00:00:00
db:BIDid:107206date:2019-02-01T00:00:00
db:JVNDBid:JVNDB-2018-014431date:2019-03-22T00:00:00
db:CNNVDid:CNNVD-201902-048date:2019-03-05T00:00:00
db:NVDid:CVE-2018-15778date:2024-11-21T03:51:27.087

SOURCES RELEASE DATE

db:VULHUBid:VHN-126071date:2019-02-04T00:00:00
db:BIDid:107206date:2019-02-01T00:00:00
db:JVNDBid:JVNDB-2018-014431date:2019-03-22T00:00:00
db:CNNVDid:CNNVD-201902-048date:2019-02-04T00:00:00
db:NVDid:CVE-2018-15778date:2019-02-04T22:29:00.297