CVE-2018-1841 describes a vulnerability in IBM Cloud Private 2.1.0 where a local user can access the Certificate Authority (CA) private key due to it being world-readable on boot/master nodes. This medium-severity flaw (CVSS 5.5) allows an attacker with local access to compromise the confidentiality of the CA private key, potentially leading to unauthorized access or impersonation within the affected system. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.0CPE matchmatch criteria | cpe:2.3:a:ibm:cloud_private:2.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.