CVE-2018-1128: It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
CSIRTS triage
- What
- Cephx authentication protocol does not properly verify clients and is vulnerable to replay attacks.
- Who is affected
- Ceph cluster deployments where attackers have network access to sniff cluster traffic.
- Urgency
- High priority; unauthenticated cluster access possible via replay; remediation critical.
- Action
- Patch Ceph to version with cephx replay protection and credential validation fixes.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Ceph
Get an email when a new Ceph advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-1128
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2018-11280.99% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2018-1128 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for It was found
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-79804: A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e…nvd · 2026-08-25
- mediumCVE-2026-80101: A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image…nvd · 2026-08-25
- mediumCVE-2026-79793: A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this v…nvd · 2026-08-25
- mediumCVE-2026-79792: A flaw has been found in zackees transcribe-anything up to 4.1.0. Affected is the function ytd…nvd · 2026-08-25
- highCVE-2026-55620: eml_parser serves as a python module for parsing eml files and returning various information f…nvd · 2026-08-25
- mediumCVE-2026-55619: eml_parser serves as a python module for parsing eml files and returning various information f…nvd · 2026-08-25
More from Microsoft Security Response Center
- lowCVE-2026-14673: PostgreSQL amcheck does not clear untrusted search path2026-08-11
- criticalCVE-2026-69836: Microsoft Entra ID Remote Code Execution Vulnerability2026-08-11
- mediumCVE-2026-53792: rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block2026-08-11
- highCVE-2026-70347: Windows Installer Elevation of Privilege Vulnerability2026-08-11
- highCVE-2026-64909: Microsoft Office Remote Code Execution Vulnerability2026-08-11