CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2018-1128

unknowncovered by 1 sourcefirst seen 2026-08-06

CSIRTS triage

What
Cephx authentication protocol does not properly verify clients and is vulnerable to replay attacks.
Who is affected
Ceph cluster deployments where attackers have network access to sniff cluster traffic.
Urgency
High priority; unauthenticated cluster access possible via replay; remediation critical.
Action
Patch Ceph to version with cephx replay protection and credential validation fixes.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2018-1128

Get an email if CVE-2018-1128 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2018-1128

CVE.org record

Embed the live status

CVE-2018-1128 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2018-1128 status](https://www.csirts.com/badge/CVE-2018-1128)](https://www.csirts.com/cve/CVE-2018-1128)