PoC Index

CVE-2017-18001

HIGH 10.0EPSS 13.8%

Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
13.82% chance of exploitation in the next 30 days, 96th percentile
Published
2017-12-31
Updated
2024-08-05

ExploitDB entries (1)

References

Related