Skip to main content

Insufficiently Protected Credentials

CVE-2018-13390

Severity Medium
Score 6.1/10

Summary

Unauthenticated access to cloudtoken daemon on Linux via network from versions 0.1.1 through 0.1.23 allows attackers on the same subnet to gain temporary AWS credentials for the users' roles.

  • LOW
  • ADJACENT_NETWORK
  • LOW
  • CHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-522 - Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Advisory Timeline

  • Published