Skip to main content
Version: latest

CVE-2018-20839

CVE Details

CVE-2018-20839

Last Update

8/16/2024

NIST CVE Summary

Systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled.

Our Official Summary

Waiting on a fix from third party mongodb & calico vendors.

CVE Severity

9.8

Status

Ongoing

Affected Products & Versions

  • Palette VerteX 4.4.14

Revision History

  • 1.0 08/16/2024 Initial Publication
  • 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products