Vulnerability Description
In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unapproved SSH encryption protocols or cipher suites also violates the Data Protection TSR (Technical Security Requirements).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Versa-Networks | Versa Operating System | - |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/1168196Third Party Advisory
- https://hackerone.com/reports/1168196Third Party Advisory
FAQ
What is CVE-2018-16499?
CVE-2018-16499 is a vulnerability with a CVSS score of 5.9 (MEDIUM). In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unapproved SSH encryption p...
How severe is CVE-2018-16499?
CVE-2018-16499 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-16499?
Check the references section above for vendor advisories and patch information. Affected products include: Versa-Networks Versa Operating System.