CVE-2017-14003

UnknownEPSS 2.60%

Last modified

CVE-2017-14003 is a vulnerability of currently unknown severity. An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by accessing a specific uniform resource locator.. EPSS estimates a 2.60% chance of exploitation in the next 30 days.

Description

An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by accessing a specific uniform resource locator.

Metrics

EPSS Probability
2.60%

83.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LavalinkEther-Serial Link Firmware<= 6.01.00\/29.03.2007

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-14003?
An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by accessing a specific uniform resource locator.
How severe is CVE-2017-14003?
Severity scoring for CVE-2017-14003 is pending analysis. The EPSS model estimates a 2.60% probability of exploitation in the next 30 days.
How do I fix CVE-2017-14003?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-14003?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST