Vulnerability Details CVE-2018-11082
Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.6%
CVSS Severity
CVSS v3 Score 6.6
CVSS v2 Score 5.0
Products affected by CVE-2018-11082
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:2.3.0
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:2.3.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:2.4.0
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:2.5.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:2.6.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:2.7.0.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:2.7.0.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:2.7.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:2.7.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:2.7.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:2.7.4.6
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:3.0.0
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:3.0.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:3.1.0
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:3.2.0
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:3.2.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:3.3.0
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:3.3.0.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:3.4.0
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:3.4.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:3.4.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:4.10.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:4.12.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:4.12.4
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:4.19.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:4.5.7
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:4.7.6
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:10
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:11
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:11.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:11.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:11.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:11.4
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:11.5
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:11.7
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:12
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:12.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:12.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:12.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:12.4
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:12.5
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:12.6
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.10
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.11
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.12
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.13
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.14
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.15
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.16
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.17
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.18
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.4
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.5
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.6
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.7
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.8
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:13.9
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:14
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:15
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:16
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:17
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:18
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:19
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:20
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:21
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:22
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:23
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.10
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.11
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.12
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.13
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.14
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.4
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.5
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.6
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.7
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.8
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:24.9
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:25
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:26
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:27
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:28
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:29
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:30
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:30.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:30.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:30.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:30.4
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:30.5
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:30.6
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:30.7
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:30.8
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:30.9
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:31
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:32
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:33
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:34
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:34.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:34.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:34.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:35
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:36
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:37
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:38
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:39
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:4
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:40
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:41
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:41.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:43
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:44
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45.10
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45.11
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45.4
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45.5
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45.6
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45.7
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45.8
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:45.9
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:48
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:5
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:50
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:51
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:52
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:52.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:52.10
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:52.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:52.4
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:52.5
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:52.6
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:52.7
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:52.8
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:52.9
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:53
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:53.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:53.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:53.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:54
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:55
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:55.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:55.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:56
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:57
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:57.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:57.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:57.3
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:57.4
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:58
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:58.1
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:59
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:6
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:60
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:60.2
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:7
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:8
-
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:9