ZeroHour

CVE-2017-18001

PoC ×2
CVSS 3.0
9.8 critical
EPSS
14%p96
Published
()
Modified
Description

Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.

Vendors
trustwave
Products
secure web gateway
Weakness
CWE-306
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.