CVE-2017-4931
Last modified
CVE-2017-4931 is a vulnerability of currently unknown severity. VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add malicious data to an enrolled device's log files. Successful exploitation of this issue could result in an unsuspecting AWC user opening a CSV file which contains malicious content.. EPSS estimates a 1.26% chance of exploitation in the next 30 days.
Description
VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add malicious data to an enrolled device's log files. Successful exploitation of this issue could result in an unsuspecting AWC user opening a CSV file which contains malicious content.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Airwatch | >= 9.0.0, < 9.2.0 |
References
- http://www.securityfocus.com/bid/101772Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039750Third Party Advisory, VDB Entry
- https://www.vmware.com/us/security/advisories/VMSA-2017-0016.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/101772Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039750Third Party Advisory, VDB Entry
- https://www.vmware.com/us/security/advisories/VMSA-2017-0016.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-4931?
How severe is CVE-2017-4931?
How do I fix CVE-2017-4931?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-4925VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0…5.5
- CVE-2017-4926VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulne…
- CVE-2017-4927VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to …
- CVE-2017-4928The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and…
- CVE-2017-4929VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) …
- CVE-2017-4930VMware AirWatch Console 9.x prior to 9.2.0 contains a vulner…
- CVE-2017-4932VMware AirWatch Launcher for Android prior to 3.2.2 contains…
- CVE-2017-4933VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (…8.8
- CVE-2017-4934VMware Workstation (12.x before 12.5.8) and Fusion (8.x befo…
- CVE-2017-4935VMware Workstation (12.x before 12.5.8) and Horizon View Cli…
- CVE-2017-4936VMware Workstation (12.x before 12.5.8) and Horizon View Cli…
- CVE-2017-4937VMware Workstation (12.x before 12.5.8) and Horizon View Cli…
Are you affected by CVE-2017-4931?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
