Description
Mycroft AI mycroft-core version 18.2.8b and earlier contains a Incorrect Access Control vulnerability in Websocket configuration that can result in code execution. This impacts ONLY the Mycroft for Linux and "non-enclosure" installs - Mark 1 and Picroft unaffected. This attack appear to be exploitable remote access to the unsecured websocket server. This vulnerability appears to have been fixed in No fix currently available.
Published: 2018-07-09
Score: 8.1 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-1956 Mycroft AI mycroft-core version 18.2.8b and earlier contains a Incorrect Access Control vulnerability in Websocket configuration that can result in code execution. This impacts ONLY the Mycroft for Linux and "non-enclosure" installs - Mark 1 and Picroft unaffected. This attack appear to be exploitable remote access to the unsecured websocket server. This vulnerability appears to have been fixed in No fix currently available.
History

No history.

Subscriptions

Linux Linux Kernel
Mycroft Mycroft-core
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-17T00:56:16.911Z

Reserved: 2018-07-09T00:00:00.000Z

Link: CVE-2018-1000621

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-09T20:29:00.783

Modified: 2024-11-21T03:40:15.130

Link: CVE-2018-1000621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses