CVE-2017-3222
Last modified
CVE-2017-3222 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Hard-coded credentials in AmosConnect 8 allow remote attackers to gain full administrative privileges, including the ability to execute commands on the Microsoft Windows host platform with SYSTEM privileges by abusing AmosConnect Task Manager.. EPSS estimates a 7.41% chance of exploitation in the next 30 days.
Description
Hard-coded credentials in AmosConnect 8 allow remote attackers to gain full administrative privileges, including the ability to execute commands on the Microsoft Windows host platform with SYSTEM privileges by abusing AmosConnect Task Manager.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Inmarsat | Amosconnect | 8.0 |
| Inmarsat | Amosconnect | 8.0.1 |
| Inmarsat | Amosconnect | 8.0.2 |
| Inmarsat | Amosconnect | 8.2.0 |
| Inmarsat | Amosconnect | 8.2.1 |
| Inmarsat | Amosconnect | 8.2.2 |
| Inmarsat | Amosconnect | 8.3.0 |
| Inmarsat | Amosconnect | 8.3.1 |
| Inmarsat | Amosconnect | 8.4.0 |
| Inmarsat | Amosconnect | 8.4.0.1 |
References
- https://www.securityfocus.com/bid/99899Third Party Advisory, VDB Entry
- https://twitter.com/mkolsek/status/923988845783322625Third Party Advisory
- https://www.kb.cert.org/vuls/id/586501Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/99899Third Party Advisory, VDB Entry
- https://twitter.com/mkolsek/status/923988845783322625Third Party Advisory
- https://www.kb.cert.org/vuls/id/586501Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-3222?
How severe is CVE-2017-3222?
How do I fix CVE-2017-3222?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-3215The Milwaukee ONE-KEY Android mobile application uses bearer…
- CVE-2017-3216WiMAX routers based on the MediaTek SDK (libmtk) that use a …
- CVE-2017-3217CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SM…
- CVE-2017-3218Samsung Magician 5.0 fails to validate TLS certificates for …
- CVE-2017-3219Acronis True Image up to and including version 2017 Build 80…
- CVE-2017-3221Blind SQL injection in Inmarsat AmosConnect 8 login form all…
- CVE-2017-3223Dahua IP camera products using firmware versions prior to V2…
- CVE-2017-3224Open Shortest Path First (OSPF) protocol implementations may…
- CVE-2017-3225Das U-Boot is a device bootloader that can read its configur…
- CVE-2017-3226Das U-Boot is a device bootloader that can read its configur…
- CVE-2017-3228Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2017-3229Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2017-3222?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
