{ "id": "CVE-2017-14331", "sourceIdentifier": "cve@mitre.org", "published": "2017-10-23T08:29:00.353", "lastModified": "2019-10-03T00:03:26.223", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the \"exsh restricted shell\" protection mechanism and obtain an interactive shell." }, { "lang": "es", "value": "Extreme EXOS en versiones 16.x, 21.x y 22.x permite que los administradores omitan el mecanismo de protecci\u00c3\u00b3n \"exsh restricted shell\" y obtener un shell interactivo." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 6.7, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 0.8, "impactScore": 5.9 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE", "baseScore": 7.2 }, "baseSeverity": "HIGH", "exploitabilityScore": 3.9, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:15.7:*:*:*:*:*:*:*", "matchCriteriaId": "10A3F12F-B2C4-430C-A17C-1D7E644DA1EA" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "4E4413DB-0B93-4111-B5A4-E6F35D7C6BF8" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "6C6EAFB3-3747-4F28-A3E7-EE6BB32E82E9" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "47CD1A1D-86F8-4421-9728-2C150562576C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.2:*:*:*:*:*:*:*", "matchCriteriaId": "46FA8F0C-C560-4E34-BBA1-3DB8793458A7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.2.2:*:*:*:*:*:*:*", "matchCriteriaId": "477D6932-555D-4563-BCB8-FDDB537E1FED" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.2.3:*:*:*:*:*:*:*", "matchCriteriaId": "EA9DBA4C-46D8-4094-B0AB-2682E77FBE70" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.2.4:*:*:*:*:*:*:*", "matchCriteriaId": "49C73AFB-C826-4370-BC69-AFE3C1575465" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:21.1:*:*:*:*:*:*:*", "matchCriteriaId": "1409DBBE-EADF-4237-BD2D-32EE2D28C985" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:21.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "D9311A95-4875-4ED7-A78B-62187A1D4DB7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:21.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "97E0D1F6-B4D9-4C9D-A840-AA1460B8FEF2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:21.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "9DC4F9FE-D10C-4967-A1AA-273835DE8876" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:21.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "D0FF9EDE-448B-40DF-95B9-0924D590B8DE" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:22.1:*:*:*:*:*:*:*", "matchCriteriaId": "7AA527BE-C0CD-4CA5-9713-58371D8F1F63" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:22.2:*:*:*:*:*:*:*", "matchCriteriaId": "9C0F71B7-A9CA-4B07-9550-64761ED94433" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:22.3:*:*:*:*:*:*:*", "matchCriteriaId": "3232567C-B89C-46EA-96DB-FAB08181BC86" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:22.4:*:*:*:*:*:*:*", "matchCriteriaId": "5A18321A-679E-4890-ACEA-CBD9231E3E18" } ] } ] } ], "references": [ { "url": "https://extremeportal.force.com/ExtrArticleDetail?n=000017719", "source": "cve@mitre.org", "tags": [ "Mitigation", "Vendor Advisory" ] } ] }