CVE-2017-0913
Last modified
CVE-2017-0913 is a vulnerability of currently unknown severity. Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a docker container. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a docker container. Successful exploitation requires valid credentials to an account with "Edit" access to "System Customization".
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ubnt | Ucrm | >= 2.3.0, <= 2.7.7 |
References
- https://hackerone.com/reports/301406Third Party Advisory
- https://hackerone.com/reports/301406Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-0913?
How severe is CVE-2017-0913?
How do I fix CVE-2017-0913?
Are you affected by CVE-2017-0913?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
