CVE-2018-1240 describes an information exposure vulnerability in Dell EMC ViPR Controller versions after 3.0.0.38, specifically within its VRRP implementation. The vulnerability stems from an insecure default configuration in Linux's keepalived component, which transmits the cluster password in plaintext via multicast. An attacker with access to the vCloud subnet where ViPR is deployed could sniff this password, potentially taking over the cluster's virtual IP and causing a denial of service. Rated with a CVSS score of 8.0 (HIGH), this vulnerability has an attack vector of Adjacent Network (AV:A) and low attack complexity (AC:L), requiring only low privileges (PR:L). The potential impact includes high confidentiality, integrity, and availability compromise (C:H/I:H/A:H). There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, or entries in ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0.39, < 3.6.1.4CPE matchmatch criteria | cpe:2.3:a:emc:vipr_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.