ID

VAR-201806-1558


CVE

CVE-2018-8902


TITLE

Avalanche Cryptographic vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-006852

DESCRIPTION

An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access potentially confidential stored data, which may include Wi-Fi passwords. This discovered key can be used for all instances of the product. Avalanche Contains a cryptographic vulnerability.Information may be obtained

Trust: 1.62

sources: NVD: CVE-2018-8902 // JVNDB: JVNDB-2018-006852

IOT TAXONOMY

category:['vehicle device']sub_category:mobile device

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:ivantimodel:avalanchescope:lteversion:6.2

Trust: 1.0

vendor:ivantimodel:avalanchescope:gteversion:5.3

Trust: 1.0

vendor:ivantimodel:avalanchescope:eqversion:5.3 to 6.2

Trust: 0.8

sources: JVNDB: JVNDB-2018-006852 // NVD: CVE-2018-8902

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-8902
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-8902
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201807-019
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2018-8902
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2018-8902
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: JVNDB: JVNDB-2018-006852 // CNNVD: CNNVD-201807-019 // NVD: CVE-2018-8902

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.0

problemtype:CWE-310

Trust: 0.8

sources: JVNDB: JVNDB-2018-006852 // NVD: CVE-2018-8902

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201807-019

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201807-019

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-006852

PATCH

title:6.2.2 Security Patchurl:https://community.ivanti.com/docs/DOC-68406

Trust: 0.8

title:Ivanti Avalanche Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=81645

Trust: 0.6

sources: JVNDB: JVNDB-2018-006852 // CNNVD: CNNVD-201807-019

EXTERNAL IDS

db:NVDid:CVE-2018-8902

Trust: 2.5

db:JVNDBid:JVNDB-2018-006852

Trust: 0.8

db:CNNVDid:CNNVD-201807-019

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

sources: OTHER: None // JVNDB: JVNDB-2018-006852 // CNNVD: CNNVD-201807-019 // NVD: CVE-2018-8902

REFERENCES

url:https://community.ivanti.com/docs/doc-68406

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-8902

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-8902

Trust: 0.8

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // JVNDB: JVNDB-2018-006852 // CNNVD: CNNVD-201807-019 // NVD: CVE-2018-8902

SOURCES

db:OTHERid: -
db:JVNDBid:JVNDB-2018-006852
db:CNNVDid:CNNVD-201807-019
db:NVDid:CVE-2018-8902

LAST UPDATE DATE

2025-01-30T21:05:42.804000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2018-006852date:2018-09-03T00:00:00
db:CNNVDid:CNNVD-201807-019date:2019-10-23T00:00:00
db:NVDid:CVE-2018-8902date:2024-11-21T04:14:34.010

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2018-006852date:2018-09-03T00:00:00
db:CNNVDid:CNNVD-201807-019date:2018-07-02T00:00:00
db:NVDid:CVE-2018-8902date:2018-06-29T15:29:00.443