9

CVE-2017-17384

ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ispconfig ≫ Ispconfig Version 3.0.2
Ispconfig ≫ Ispconfig Version 3.0.2.1
Ispconfig ≫ Ispconfig Version 3.0.2.2
Ispconfig ≫ Ispconfig Version 3.0.2.2 Update b1
Ispconfig ≫ Ispconfig Version 3.0.3
Ispconfig ≫ Ispconfig Version 3.0.3 Update b1
Ispconfig ≫ Ispconfig Version 3.0.3 Update rc1
Ispconfig ≫ Ispconfig Version 3.0.3.1
Ispconfig ≫ Ispconfig Version 3.0.3.1 Update rc1
Ispconfig ≫ Ispconfig Version 3.0.3.1 Update rc2
Ispconfig ≫ Ispconfig Version 3.0.3.2
Ispconfig ≫ Ispconfig Version 3.0.3.2 Update rc1
Ispconfig ≫ Ispconfig Version 3.0.3.3
Ispconfig ≫ Ispconfig Version 3.0.3.3 Update rc1
Ispconfig ≫ Ispconfig Version 3.0.4
Ispconfig ≫ Ispconfig Version 3.0.4 Update b1
Ispconfig ≫ Ispconfig Version 3.0.4.1
Ispconfig ≫ Ispconfig Version 3.0.4.1 Update rc1
Ispconfig ≫ Ispconfig Version 3.0.4.1 Update rc2
Ispconfig ≫ Ispconfig Version 3.0.4.2
Ispconfig ≫ Ispconfig Version 3.0.4.3
Ispconfig ≫ Ispconfig Version 3.0.4.6
Ispconfig ≫ Ispconfig Version 3.0.4.6 Update rc1
Ispconfig ≫ Ispconfig Version 3.0.5
Ispconfig ≫ Ispconfig Version 3.0.5 Update alpha1
Ispconfig ≫ Ispconfig Version 3.0.5 Update b1
Ispconfig ≫ Ispconfig Version 3.0.5 Update rc1
Ispconfig ≫ Ispconfig Version 3.0.5 Update rc2
Ispconfig ≫ Ispconfig Version 3.0.5.1
Ispconfig ≫ Ispconfig Version 3.0.5.2
Ispconfig ≫ Ispconfig Version 3.0.5.3
Ispconfig ≫ Ispconfig Version 3.0.5.4
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update b1
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update p1
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update p2
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update p3
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update p4
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update p5
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update p6
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update p7
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update p8
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update p9
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update rc1
Ispconfig ≫ Ispconfig Version 3.0.5.4 Update rc2
Ispconfig ≫ Ispconfig Version 3.1
Ispconfig ≫ Ispconfig Version 3.1.1
Ispconfig ≫ Ispconfig Version 3.1.1 Update p1
Ispconfig ≫ Ispconfig Version 3.1.2
Ispconfig ≫ Ispconfig Version 3.1.3
Ispconfig ≫ Ispconfig Version 3.1.4
Ispconfig ≫ Ispconfig Version 3.1.5
Ispconfig ≫ Ispconfig Version 3.1.6
Ispconfig ≫ Ispconfig Version 3.1.7
Ispconfig ≫ Ispconfig Version 3.1.7 Update p1
Ispconfig ≫ Ispconfig Version 3.1.8
Ispconfig ≫ Ispconfig Version 3.1.8 Update p1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.49% 0.707
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://www.ispconfig.org/blog/ispconfig-3-1-9-released-important-security-update/
Patch
Vendor Advisory
Issue Tracking