PoC Index

CVE-2017-13664

CRITICAL 9.8EPSS 1.5%

Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.54% chance of exploitation in the next 30 days, 73th percentile
Published
2017-12-01
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related