CVE-2018-1154

LOW

Description

In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this issue.

References

http://www.securitytracker.com/id/1041431

https://www.tenable.com/security/tns-2018-11

Details

Source: MITRE

Published: 2018-08-02

Updated: 2018-10-03

Type: CWE-255

Risk Information

CVSS v2.0

Base Score: 3.3

Vector: (AV:A/AC:L/Au:N/C:P/I:N/A:N)

Impact Score: 2.9

Exploitability Score: 6.5

Severity: LOW

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH