CVE-2018-11750

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
02/10/2018
Last modified:
02/01/2019

Description

Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As of the 0.4.0 release of cisco_ios, host key checking is enabled by default.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:puppet:cisco_ios_module:*:*:*:*:*:puppet:*:* 0.4.0 (excluding)