NewStart CGSL MAIN 6.06 : docker-image-check Multiple Vulnerabilities (NS-SA-2026-0055)

critical Nessus Plugin ID 330494

Synopsis

The remote NewStart CGSL host is affected by multiple vulnerabilities.

Description

The remote NewStart CGSL host, running version MAIN 6.06, has docker-image-check packages installed that are affected by multiple vulnerabilities:

- net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port number. For example, an attacker can compose a crafted javascript:// URL that results in a hostname of google.com. (CVE-2019-14809)

- The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.
(CVE-2018-16875)

- Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. (CVE-2019-16276)

- Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks. (CVE-2019-6486)

- Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs. (CVE-2020-16845)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the vulnerable CGSL docker-image-check packages. Note that updated packages may not be available yet. Please contact ZTE for more information.

See Also

https://security.gd-linux.com/info/CVE-2018-16875

https://security.gd-linux.com/info/CVE-2019-14809

https://security.gd-linux.com/info/CVE-2019-16276

https://security.gd-linux.com/info/CVE-2019-6486

https://security.gd-linux.com/info/CVE-2020-16845

https://security.gd-linux.com/info/CVE-2020-28362

https://security.gd-linux.com/notice/NS-SA-2026-0055

Plugin Details

Severity: Critical

ID: 330494

File Name: newstart_cgsl_NS-SA-2026-0055_docker-image-check.nasl

Version: 1.1

Type: Local

Published: 7/29/2026

Updated: 7/29/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-14809

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:zte:cgsl_main:6, p-cpe:/a:zte:cgsl_main:docker-image-check

Required KB Items: Host/local_checks_enabled, Host/ZTE-CGSL/release, Host/ZTE-CGSL/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/27/2026

Vulnerability Publication Date: 12/13/2018

Reference Information

CVE: CVE-2018-16875, CVE-2019-14809, CVE-2019-16276, CVE-2019-6486, CVE-2020-16845, CVE-2020-28362