CVE-2018-11752

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
02/10/2018
Last modified:
01/05/2020

Description

Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every run. These issues have been resolved in the 0.4.0 release.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:puppet:cisco_ios:*:*:*:*:*:puppet:*:* 0.4.0 (excluding)


References to Advisories, Solutions, and Tools