CVE-2018-1237

Description

Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA). This component is deployed on every server in the ScaleIO cluster and is used for central management of ScaleIO nodes. A remote malicious user, having network access to LIA, could potentially exploit this vulnerability to launch brute force guessing of user names and passwords of user accounts on the LIA.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.32

Associated Vulnerability

VulnerabilityOS Platform
Mozilla Firefox (61.0)Windows
Mozilla Firefox (x64) (61.0)Windows
Mozilla Firefox ESR (60.1.0)Windows
Mozilla Firefox ESR (x64) (60.1.0)Windows
Mozilla Thunderbird (52.9.0)Windows
Mozilla Firefox (61.0.1)Windows
Mozilla Firefox (x64) (61.0.1)Windows
Mozilla Thunderbird (52.9.1)Windows
Mozilla Firefox (61.0.2)Windows
Mozilla Firefox (x64) (61.0.2)Windows
Mozilla Firefox (62.0)Windows
Mozilla Firefox (x64) (62.0)Windows
Mozilla Firefox ESR (60.2.0)Windows
Mozilla Firefox ESR (x64) (60.2.0)Windows
Mozilla Firefox (62.0.2)Windows
Mozilla Firefox ESR (60.2.1)Windows
Mozilla Firefox (x64) (62.0.2)Windows
Mozilla Firefox ESR (x64) (60.2.1)Windows
Mozilla Thunderbird (60.2.1)Windows
Mozilla Firefox (62.0.3)Windows
Mozilla Firefox ESR (60.2.2)Windows
Mozilla Firefox (x64) (62.0.3)Windows
Mozilla Firefox ESR (x64) (60.2.2)Windows
Upgrade LibreOffice (x64) 6.0.0 to latest versionWindows
Upgrade libreoffice 6.0.0 to latest versionWindows
Mozilla Thunderbird (60.0)Windows
Mozilla Thunderbird (60.3.0)Windows
Mozilla Thunderbird (60.3.1)Windows
Mozilla Thunderbird (60.3.2)Windows
Mozilla Thunderbird (60.3.3)Windows
Mozilla Thunderbird (60.4.0)Windows
Mozilla Thunderbird (60.5.0)Windows
Mozilla Thunderbird (60.5.1)Windows
Improper Authentication Vulnerability (CVE-2018-1237)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-307718Mozilla Firefox (61.0)
PATCH-307725Mozilla Firefox (x64) (61.0)
PATCH-307747Mozilla Firefox ESR (60.1.0)
PATCH-307748Mozilla Firefox ESR (x64) (60.1.0)
PATCH-307749Mozilla Thunderbird (52.9.0)
PATCH-307753Mozilla Firefox (61.0.1)
PATCH-307758Mozilla Firefox (x64) (61.0.1)
PATCH-307789Mozilla Thunderbird (52.9.1)
PATCH-307919Mozilla Firefox (61.0.2)
PATCH-307924Mozilla Firefox (x64) (61.0.2)
PATCH-308023Mozilla Firefox (62.0)
PATCH-308025Mozilla Firefox (x64) (62.0)
PATCH-308027Mozilla Firefox ESR (60.2.0)
PATCH-308035Mozilla Firefox ESR (x64) (60.2.0)
PATCH-308122Mozilla Firefox (62.0.2)
PATCH-308123Mozilla Firefox ESR (60.2.1)
PATCH-308124Mozilla Firefox (x64) (62.0.2)
PATCH-308125Mozilla Firefox ESR (x64) (60.2.1)
PATCH-308155Mozilla Thunderbird (60.2.1)
PATCH-308180Mozilla Firefox (62.0.3)
PATCH-308181Mozilla Firefox ESR (60.2.2)
PATCH-308182Mozilla Firefox (x64) (62.0.3)
PATCH-308183Mozilla Firefox ESR (x64) (60.2.2)
PATCH-343131LibreOffice (x64) (24.8.3)
PATCH-307102Updates for LibreOffice (6.0.1)
PATCH-307900Mozilla Thunderbird (60.0)
PATCH-308341Mozilla Thunderbird (60.3.0)
PATCH-308412Mozilla Thunderbird (60.3.1)
PATCH-308522Mozilla Thunderbird (60.3.2)
PATCH-308580Mozilla Thunderbird (60.3.3)
PATCH-308671Mozilla Thunderbird (60.4.0)
PATCH-308875Mozilla Thunderbird (60.5.0)
PATCH-308999Mozilla Thunderbird (60.5.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234