CVE Vulnerabilities in 2018

30 documented vulnerabilities published in 2018.

Other years: 2026 2025 2024 2023 2022 2021 2020

Top Affected Vendors in 2018

All CVEs from 2018

CVE-2017-15031
7.5 high

In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.

Trustedfirmware Trusted Firmware-A Dec 18, 2018
CVE-2018-17924
8.6 high

Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in

Rockwellautomation Micrologix 1400 Firmware Dec 7, 2018
CVE-2018-19608
4.7 medium

Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.

Arm Mbed Tls Dec 5, 2018
CVE-2018-6439
7.8 high

A Vulnerability in the configdownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, gain root access.

Broadcom Fabric Operating System Dec 3, 2018
CVE-2018-7798
8.2 high

A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device.

Schneider-Electric Somachine Basic Nov 2, 2018
CVE-2018-7792
7.5 high

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to decode the password using rainbow table.

Schneider-Electric Modicon M221 Firmware Aug 29, 2018
CVE-2018-7791
9.8 critical

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the original password with their password. If an attacker exploits this

Schneider-Electric Modicon M221 Firmware Aug 29, 2018
CVE-2018-7790
9.8 critical

An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If an attacker exploits this vulnerability and connects to a Mo

Schneider-Electric Modicon M221 Firmware Aug 29, 2018
CVE-2018-7795
5.4 medium

A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of java script code.

Schneider-Electric Powerlogic Pm5560 Firmware Aug 29, 2018
CVE-2018-7789
7.5 high

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to remotely reboot Modicon M221 using crafted programing protocol frames.

Schneider-Electric Modicon M221 Firmware Aug 29, 2018
CVE-2018-3646
5.6 medium

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.

Intel Core I3 Aug 14, 2018
CVE-2018-3620
5.6 medium

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.

Intel Core I3 Aug 14, 2018
CVE-2018-3615
7.3 high

Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.

Intel Core I3 Aug 14, 2018
CVE-2018-10626
4.4 medium

Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLin

Medtronic Mycarelink 24952 Patient Monitor Firmware Aug 10, 2018
CVE-2018-10622
6.8 medium

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.

Medtronic Mycarelink 24952 Patient Monitor Firmware Aug 10, 2018
CVE-2018-1002206
5.5 medium

SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

Adamhathcock Sharpcompress Jul 25, 2018
CVE-2018-8859
9.8 critical

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when speci

Echelon Smartserver 1 Firmware Jul 24, 2018
CVE-2018-8855
9.8 critical

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP.

Echelon Smartserver 1 Firmware Jul 24, 2018
CVE-2018-8851
9.8 critical

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.

Echelon Smartserver 1 Firmware Jul 24, 2018
CVE-2018-10627
9.8 critical

Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and FTP servers. This vu

Echelon Smartserver 1 Firmware Jul 24, 2018
CVE-2018-13785
6.5 medium

In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.

Libpng Libpng Jul 9, 2018
CVE-2018-12594
7.5 high

Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct request for the data/fileinfo.xml or job/job.json file, as demonstrated the Master Password field.

Reliablecontrols Mach-Prowebcom Firmware Jun 20, 2018
CVE-2018-12437
4.9 medium

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

Libtom Libtomcrypt Jun 15, 2018
CVE-2018-3639
5.5 medium

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store B

Intel Atom C May 22, 2018