CVE-2017-4931
Last modified
CVE-2017-4931 is a vulnerability of currently unknown severity. VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add malicious data to an enrolled device's log files. Successful exploitation of this issue could result in an unsuspecting AWC user opening a CSV file which contains malicious content.. EPSS estimates a 1.26% chance of exploitation in the next 30 days.
Description
VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add malicious data to an enrolled device's log files. Successful exploitation of this issue could result in an unsuspecting AWC user opening a CSV file which contains malicious content.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Airwatch | >= 9.0.0, < 9.2.0 |
References
- http://www.securityfocus.com/bid/101772Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039750Third Party Advisory, VDB Entry
- https://www.vmware.com/us/security/advisories/VMSA-2017-0016.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/101772Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039750Third Party Advisory, VDB Entry
- https://www.vmware.com/us/security/advisories/VMSA-2017-0016.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-4931?
How severe is CVE-2017-4931?
How do I fix CVE-2017-4931?
Are you affected by CVE-2017-4931?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
