Vulnerability Description
Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sphinxsearch | Sphinx | 3.1.1 |
Related Weaknesses (CWE)
References
- http://sphinxsearch.com/docs/sphinx3.html#getting-started-on-linux-and-macosVendor Advisory
- https://blog.wirhabenstil.de/2019/08/19/sphinxsearch-0-0-0-09306-cve-2019-14511/ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://sphinxsearch.com/blog/Release Notes
- http://sphinxsearch.com/docs/sphinx3.html#getting-started-on-linux-and-macosVendor Advisory
- https://blog.wirhabenstil.de/2019/08/19/sphinxsearch-0-0-0-09306-cve-2019-14511/ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://sphinxsearch.com/blog/Release Notes
FAQ
What is CVE-2019-14511?
CVE-2019-14511 is a vulnerability with a CVSS score of 7.5 (HIGH). Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).
How severe is CVE-2019-14511?
CVE-2019-14511 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14511?
Check the references section above for vendor advisories and patch information. Affected products include: Sphinxsearch Sphinx.