CVE-2018-1281
Last modified
CVE-2018-1281 is a vulnerability of currently unknown severity. The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via the DMLC_PS_ROOT_URI and DMLC_PS_ROOT_PORT env variables. In versions older than 1.0.0, however, the MXNet framework will listen on 0.0.0.0 rather than user specified DMLC_PS_ROOT_URI once a scheduler node is initialized. EPSS estimates a 1.95% chance of exploitation in the next 30 days.
Description
The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via the DMLC_PS_ROOT_URI and DMLC_PS_ROOT_PORT env variables. In versions older than 1.0.0, however, the MXNet framework will listen on 0.0.0.0 rather than user specified DMLC_PS_ROOT_URI once a scheduler node is initialized. This exposes the instance running MXNet to any attackers reachable via the interface they didn't expect to be listening on. For example: If a user wants to run a clustered setup locally, they may specify to run on 127.0.0.1. But since MXNet will listen on 0.0.0.0, it makes the port accessible on all network interfaces.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Mxnet | < 1.0.0 |
References
- https://github.com/dmlc/ps-lite/commit/4be817e8b03e7e92517e91f2dfcc50865e91c6eaPatch, Third Party Advisory
- https://github.com/dmlc/ps-lite/commit/4be817e8b03e7e92517e91f2dfcc50865e91c6eaPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1281?
How severe is CVE-2018-1281?
How do I fix CVE-2018-1281?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-12804Adobe Connect versions 9.7.5 and earlier have an Authenticat…
- CVE-2018-12805Adobe Connect versions 9.7.5 and earlier have an Insecure Li…
- CVE-2018-12806Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.…
- CVE-2018-12807Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.…
- CVE-2018-12808Adobe Acrobat and Reader versions 2018.011.20055 and earlier…
- CVE-2018-12809Adobe Experience Manager versions 6.4 and earlier have a Ser…
- CVE-2018-12810Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 …
- CVE-2018-12811Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 …
- CVE-2018-12812Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.01…
- CVE-2018-12813Adobe Digital Editions versions 4.5.8 and below have a heap …
- CVE-2018-12814Adobe Digital Editions versions 4.5.8 and below have a heap …
- CVE-2018-12815Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.01…
Are you affected by CVE-2018-1281?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
