AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-1240

HIGH · CVSS 8 EPSS 0.55%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-04-18 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.0. It affects Linux. It may lead to a denial-of-service condition.

CVE
CVE-2018-1240
Severity
HIGH
CVSS
8
EPSS
0.55%
Linux

Original NVD Description

Dell EMC ViPR Controller, versions after 3.0.0.38, contain an information exposure vulnerability in the VRRP. VRRP defaults to an insecure configuration in Linux's keepalived component which sends the cluster password in plaintext through multicast. A malicious user, having access to the vCloud subnet where ViPR is deployed, could potentially sniff the password and use it to take over the cluster's virtual IP and cause a denial of service on that ViPR Controller system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)