Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-16674

Опубликовано: 09 нояб. 2017
Источник: nvd
CVSS3: 8
CVSS2: 4.9
EPSS Низкий

Описание

Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command and a secondary non-whitelisted command. This affects Datto Windows Agent (DWA) 1.0.5.0 and earlier. In other words, an attacker could combine this "primary/secondary" attack with the CVE-2017-16673 "rogue pairing" attack to achieve unauthenticated access to all agent machines running these older DWA versions.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:datto:windows_agent:*:*:*:*:*:*:*:*
Версия до 1.0.5.0 (включая)

EPSS

Процентиль: 39%
0.00172
Низкий

8 High

CVSS3

4.9 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8
github
больше 3 лет назад

Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command and a secondary non-whitelisted command. This affects Datto Windows Agent (DWA) 1.0.5.0 and earlier. In other words, an attacker could combine this "primary/secondary" attack with the CVE-2017-16673 "rogue pairing" attack to achieve unauthenticated access to all agent machines running these older DWA versions.

EPSS

Процентиль: 39%
0.00172
Низкий

8 High

CVSS3

4.9 Medium

CVSS2

Дефекты

NVD-CWE-noinfo