Lucene search

K
cve[email protected]CVE-2017-17384
HistoryDec 07, 2017 - 8:29 a.m.

CVE-2017-17384

2017-12-0708:29:00
CWE-269
web.nvd.nist.gov
24
cve-2017-17384
ispconfig
root access
cron job
security vulnerability

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.8%

ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.

Affected configurations

NVD
Node
ispconfigispconfigMatch3.0.2
OR
ispconfigispconfigMatch3.0.2.1
OR
ispconfigispconfigMatch3.0.2.2
OR
ispconfigispconfigMatch3.0.2.2b1
OR
ispconfigispconfigMatch3.0.3
OR
ispconfigispconfigMatch3.0.3b1
OR
ispconfigispconfigMatch3.0.3rc1
OR
ispconfigispconfigMatch3.0.3.1
OR
ispconfigispconfigMatch3.0.3.1rc1
OR
ispconfigispconfigMatch3.0.3.1rc2
OR
ispconfigispconfigMatch3.0.3.2
OR
ispconfigispconfigMatch3.0.3.2rc1
OR
ispconfigispconfigMatch3.0.3.3
OR
ispconfigispconfigMatch3.0.3.3rc1
OR
ispconfigispconfigMatch3.0.4
OR
ispconfigispconfigMatch3.0.4b1
OR
ispconfigispconfigMatch3.0.4.1
OR
ispconfigispconfigMatch3.0.4.1rc1
OR
ispconfigispconfigMatch3.0.4.1rc2
OR
ispconfigispconfigMatch3.0.4.2
OR
ispconfigispconfigMatch3.0.4.3
OR
ispconfigispconfigMatch3.0.4.6
OR
ispconfigispconfigMatch3.0.4.6rc1
OR
ispconfigispconfigMatch3.0.5
OR
ispconfigispconfigMatch3.0.5alpha1
OR
ispconfigispconfigMatch3.0.5b1
OR
ispconfigispconfigMatch3.0.5rc1
OR
ispconfigispconfigMatch3.0.5rc2
OR
ispconfigispconfigMatch3.0.5.1
OR
ispconfigispconfigMatch3.0.5.2
OR
ispconfigispconfigMatch3.0.5.3
OR
ispconfigispconfigMatch3.0.5.4
OR
ispconfigispconfigMatch3.0.5.4b1
OR
ispconfigispconfigMatch3.0.5.4p1
OR
ispconfigispconfigMatch3.0.5.4p2
OR
ispconfigispconfigMatch3.0.5.4p3
OR
ispconfigispconfigMatch3.0.5.4p4
OR
ispconfigispconfigMatch3.0.5.4p5
OR
ispconfigispconfigMatch3.0.5.4p6
OR
ispconfigispconfigMatch3.0.5.4p7
OR
ispconfigispconfigMatch3.0.5.4p8
OR
ispconfigispconfigMatch3.0.5.4p9
OR
ispconfigispconfigMatch3.0.5.4rc1
OR
ispconfigispconfigMatch3.0.5.4rc2
OR
ispconfigispconfigMatch3.1
OR
ispconfigispconfigMatch3.1.1
OR
ispconfigispconfigMatch3.1.1p1
OR
ispconfigispconfigMatch3.1.2
OR
ispconfigispconfigMatch3.1.3
OR
ispconfigispconfigMatch3.1.4
OR
ispconfigispconfigMatch3.1.5
OR
ispconfigispconfigMatch3.1.6
OR
ispconfigispconfigMatch3.1.7
OR
ispconfigispconfigMatch3.1.7p1
OR
ispconfigispconfigMatch3.1.8
OR
ispconfigispconfigMatch3.1.8p1

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.8%

Related for CVE-2017-17384