Vulnerability Description
Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could get the contents of the corresponding seed from the published image and therefore infer the initial state of the LRNG.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Operations Manager | >= 1.12, < 1.12.22 |
Related Weaknesses (CWE)
References
- https://pivotal.io/security/cve-2018-11045MitigationVendor Advisory
- https://pivotal.io/security/cve-2018-11045MitigationVendor Advisory
FAQ
What is CVE-2018-11045?
CVE-2018-11045 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance im...
How severe is CVE-2018-11045?
CVE-2018-11045 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11045?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Operations Manager.