Lucene search

K
cvelistVulDBCVELIST:CVE-2017-20083
HistoryJun 22, 2022 - 6:10 a.m.

CVE-2017-20083 JUNG Smart Visu Server SSH Server backdoor

2022-06-2206:10:16
CWE-912
VulDB
www.cve.org
3
cve-2017-20083
jung smart visu server
ssh server
backdoor
critical vulnerability
manipulation
local attack
upgrade.

CVSS3

5.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

17.8%

A vulnerability, which was classified as critical, was found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. Affected is an unknown function of the component SSH Server. The manipulation leads to backdoor. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.

CNA Affected

[
  {
    "product": "Smart Visu Server",
    "vendor": "JUNG",
    "versions": [
      {
        "status": "affected",
        "version": "1.0.804"
      },
      {
        "status": "affected",
        "version": "1.0.830"
      },
      {
        "status": "affected",
        "version": "1.0.832"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

17.8%

Related for CVELIST:CVE-2017-20083