CVE-2018-1000621 describes an Incorrect Access Control vulnerability in Mycroft AI mycroft-core version 18.2.8b and earlier, specifically impacting Mycroft for Linux and "non-enclosure" installations. This high-severity vulnerability (CVSS 8.1) allows for remote code execution due to an unsecured websocket server. While no fix is currently available, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 18.2.8bCPE matchmatch criteria | cpe:2.3:a:mycroft:mycroft-core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.