CVE-2018-13140
UnknownEPSS 6.63%
Last modified
CVE-2018-13140 is a vulnerability of currently unknown severity. Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages.. EPSS estimates a 6.63% chance of exploitation in the next 30 days.
Description
Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Druide | Antidote 9 | <= 5.1 |
References
- http://packetstormsecurity.com/files/149468/Antidote-9.5.1-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Sep/38Exploit, Mailing List, Third Party Advisory
- https://sysdream.com/news/lab/2018-09-21-cve-2018-13140-antidote-remote-code-execution-against-the-update-component/Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/149468/Antidote-9.5.1-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Sep/38Exploit, Mailing List, Third Party Advisory
- https://sysdream.com/news/lab/2018-09-21-cve-2018-13140-antidote-remote-code-execution-against-the-update-component/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-13140?
Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages.
How severe is CVE-2018-13140?
Severity scoring for CVE-2018-13140 is pending analysis. The EPSS model estimates a 6.63% probability of exploitation in the next 30 days.
How do I fix CVE-2018-13140?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-13133Golden Frog VyprVPN before 2018-06-21 has a vulnerability as…
- CVE-2018-13134TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devi…
- CVE-2018-13136The Ultimate Member (aka ultimatemember) plugin before 2.0.1…
- CVE-2018-13137The Events Manager plugin 5.9.4 for WordPress has XSS via th…
- CVE-2018-13139A stack-based buffer overflow in psf_memset in common.c in l…
- CVE-2018-1314In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" oper…
- CVE-2018-13144The transfer and transferFrom functions of a smart contract …7.5
- CVE-2018-13145The mintToken function of a smart contract implementation fo…
- CVE-2018-13146The mintToken, buy, and sell functions of a smart contract i…
- CVE-2018-1315In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statemen…
- CVE-2018-13153In ImageMagick 7.0.8-4, there is a memory leak in the XMagic…
- CVE-2018-13155The mintToken function of a smart contract implementation fo…
Are you affected by CVE-2018-13140?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
