CVE-2017-16776
Last modified
CVE-2017-16776 is a vulnerability of currently unknown severity. Security researchers discovered an authentication bypass vulnerability in version 2.0.2 of the Conserus Workflow Intelligence application by McKesson Medical Imaging Company, which is now a Change Healthcare company. The attacker must send a malicious HTTP GET request to exploit the vulnerability. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
Security researchers discovered an authentication bypass vulnerability in version 2.0.2 of the Conserus Workflow Intelligence application by McKesson Medical Imaging Company, which is now a Change Healthcare company. The attacker must send a malicious HTTP GET request to exploit the vulnerability. The vulnerability allows an attacker to bypass authentication and escalate privileges of valid users. An unauthenticated attacker can exploit the vulnerability and be granted limited access to other accounts. An authenticated attacker can exploit the vulnerability and be granted access reserved for higher privilege users.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mckesson | Conserus Workflow Intelligence | 2.0.2 |
References
- https://technical.nttsecurity.com/post/102emjm/conserus-workflow-intelligence-authentication-bypass-vulnerabilityExploit, Third Party Advisory
- https://technical.nttsecurity.com/post/102emjm/conserus-workflow-intelligence-authentication-bypass-vulnerabilityExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-16776?
How severe is CVE-2017-16776?
How do I fix CVE-2017-16776?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-16770File and directory information exposure vulnerability in SYN…
- CVE-2017-16771Cross-site scripting (XSS) vulnerability in Log Viewer in Sy…
- CVE-2017-16772Improper input validation vulnerability in SYNOPHOTO_Flickr_…
- CVE-2017-16773Improper authorization vulnerability in Highlight Preview in…6.5
- CVE-2017-16774Cross-site scripting (XSS) vulnerability in SYNO.Core.Person…6.5
- CVE-2017-16775Improper restriction of rendered UI layers or frames vulnera…7.1
- CVE-2017-16777If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmwar…
- CVE-2017-16778An access control weakness in the DTMF tone receiver of Ferm…4.6
- CVE-2017-1678IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vul…
- CVE-2017-16780The installer in MyBB before 1.8.13 allows remote attackers …
- CVE-2017-16781The installer in MyBB before 1.8.13 has XSS.
- CVE-2017-16782In Home Assistant before 0.57, it is possible to inject Java…
Are you affected by CVE-2017-16776?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
