CVE-2018-8902

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
29/06/2018
Last modified:
03/10/2019

Description

An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access potentially confidential stored data, which may include Wi-Fi passwords. This discovered key can be used for all instances of the product.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:avalanche:*:*:*:*:*:*:*:* 5.3 (including) 6.2 (including)


References to Advisories, Solutions, and Tools