CVE-2018-19878
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
19/06/2019
Last modified:
21/06/2019
Description
An issue was discovered on Teltonika RTU950 R_31.04.89 devices. The application allows a user to login without limitation. For every successful login request, the application saves a session. A user can re-login without logging out, causing the application to store the session in memory. Exploitation of this vulnerability will increase memory use and consume free space.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:teltonika:rut950_firmware:r_31.04.89:*:*:*:*:*:*:* | ||
| cpe:2.3:h:teltonika:rut950:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



