CVE-2017-7546
UnknownEPSS 61.57%
Last modified
CVE-2017-7546 is a vulnerability of currently unknown severity. PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.. EPSS estimates a 61.57% chance of exploitation in the next 30 days.
Description
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | 9.2 |
| Postgresql | Postgresql | 9.2.1 |
| Postgresql | Postgresql | 9.2.2 |
| Postgresql | Postgresql | 9.2.3 |
| Postgresql | Postgresql | 9.2.4 |
| Postgresql | Postgresql | 9.2.5 |
| Postgresql | Postgresql | 9.2.6 |
| Postgresql | Postgresql | 9.2.7 |
| Postgresql | Postgresql | 9.2.8 |
| Postgresql | Postgresql | 9.2.9 |
| Postgresql | Postgresql | 9.2.10 |
| Postgresql | Postgresql | 9.2.11 |
| Postgresql | Postgresql | 9.2.12 |
| Postgresql | Postgresql | 9.2.13 |
| Postgresql | Postgresql | 9.2.14 |
| Postgresql | Postgresql | 9.2.15 |
| Postgresql | Postgresql | 9.2.16 |
| Postgresql | Postgresql | 9.2.17 |
| Postgresql | Postgresql | 9.2.18 |
| Postgresql | Postgresql | 9.2.19 |
| Postgresql | Postgresql | 9.2.20 |
| Postgresql | Postgresql | 9.2.21 |
| Postgresql | Postgresql | 9.3 |
| Postgresql | Postgresql | 9.3.1 |
| Postgresql | Postgresql | 9.3.2 |
| Postgresql | Postgresql | 9.3.3 |
| Postgresql | Postgresql | 9.3.4 |
| Postgresql | Postgresql | 9.3.5 |
| Postgresql | Postgresql | 9.3.6 |
| Postgresql | Postgresql | 9.3.7 |
| Postgresql | Postgresql | 9.3.8 |
| Postgresql | Postgresql | 9.3.9 |
| Postgresql | Postgresql | 9.3.10 |
| Postgresql | Postgresql | 9.3.11 |
| Postgresql | Postgresql | 9.3.12 |
| Postgresql | Postgresql | 9.3.13 |
| Postgresql | Postgresql | 9.3.14 |
| Postgresql | Postgresql | 9.3.15 |
| Postgresql | Postgresql | 9.3.16 |
| Postgresql | Postgresql | 9.3.17 |
| Postgresql | Postgresql | 9.4 |
| Postgresql | Postgresql | 9.4.1 |
| Postgresql | Postgresql | 9.4.2 |
| Postgresql | Postgresql | 9.4.3 |
| Postgresql | Postgresql | 9.4.4 |
| Postgresql | Postgresql | 9.4.5 |
| Postgresql | Postgresql | 9.4.6 |
| Postgresql | Postgresql | 9.4.7 |
| Postgresql | Postgresql | 9.4.8 |
| Postgresql | Postgresql | 9.4.9 |
Showing 50 of 66 affected configurations. See NVD for the full list.
References
- http://www.debian.org/security/2017/dsa-3935Third Party Advisory
- http://www.debian.org/security/2017/dsa-3936Third Party Advisory
- http://www.securityfocus.com/bid/100278Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039142Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2677Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2678Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2728Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2860Third Party Advisory
- https://security.gentoo.org/glsa/201710-06Third Party Advisory
- https://www.postgresql.org/about/news/1772/Vendor Advisory
- http://www.debian.org/security/2017/dsa-3935Third Party Advisory
- http://www.debian.org/security/2017/dsa-3936Third Party Advisory
- http://www.securityfocus.com/bid/100278Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039142Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2677Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2678Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2728Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2860Third Party Advisory
- https://security.gentoo.org/glsa/201710-06Third Party Advisory
- https://www.postgresql.org/about/news/1772/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7546?
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.
How severe is CVE-2017-7546?
Severity scoring for CVE-2017-7546 is pending analysis. The EPSS model estimates a 61.57% probability of exploitation in the next 30 days.
How do I fix CVE-2017-7546?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7540rubygem-safemode, as used in Foreman, versions 1.3.2 and ear…
- CVE-2017-7541The brcmf_cfg80211_mgmt_tx function in drivers/net/wireless/…7.8
- CVE-2017-7542The ip6_find_1stfragopt function in net/ipv6/output_core.c i…
- CVE-2017-7543A race-condition flaw was discovered in openstack-neutron be…5.3
- CVE-2017-7544libexif through 0.6.21 is vulnerable to out-of-bounds heap r…
- CVE-2017-7545It was discovered that the XmlUtils class in jbpmmigration 6…6.5
- CVE-2017-7547PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and…
- CVE-2017-7548PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulne…7.5
- CVE-2017-7549A flaw was found in instack-undercloud 7.2.0 as packaged in …
- CVE-2017-7550A flaw was found in the way Ansible (2.3.x before 2.3.3, and…9.8
- CVE-2017-7551389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerab…
- CVE-2017-7552A flaw was discovered in the file editor of millicore, affec…
Are you affected by CVE-2017-7546?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
