CVE-2019-0816 is a security feature bypass vulnerability in Azure SSH Keypairs, affecting Canonical Azure, Canonical Ubuntu Linux, Microsoft Azure, and Microsoft Ubuntu Linux. This flaw stems from a change in the provisioning logic for certain Linux images utilizing cloud-init. Rated as Medium severity (CVSS 5.1), it has a local attack vector with high attack complexity, allowing for a high impact on integrity without affecting confidentiality or availability. There is no evidence of active exploitation, nor are there known public exploits or Metasploit modules, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.