{ "id": "CVE-2017-14332", "sourceIdentifier": "cve@mitre.org", "published": "2017-10-23T08:29:00.400", "lastModified": "2019-10-03T00:03:26.223", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values." }, { "lang": "es", "value": "Extreme EXOS en versiones 15.7, 16.x, 21.x y 22.x permite que atacantes secuestren sesiones determinando valores SessionID." } ], "metrics": { "cvssMetricV30": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 8.1, "baseSeverity": "HIGH" }, "exploitabilityScore": 2.2, "impactScore": 5.9 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 6.8 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:15.7:*:*:*:*:*:*:*", "matchCriteriaId": "10A3F12F-B2C4-430C-A17C-1D7E644DA1EA" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "4E4413DB-0B93-4111-B5A4-E6F35D7C6BF8" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "6C6EAFB3-3747-4F28-A3E7-EE6BB32E82E9" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "47CD1A1D-86F8-4421-9728-2C150562576C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.2:*:*:*:*:*:*:*", "matchCriteriaId": "46FA8F0C-C560-4E34-BBA1-3DB8793458A7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.2.2:*:*:*:*:*:*:*", "matchCriteriaId": "477D6932-555D-4563-BCB8-FDDB537E1FED" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.2.3:*:*:*:*:*:*:*", "matchCriteriaId": "EA9DBA4C-46D8-4094-B0AB-2682E77FBE70" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:16.2.4:*:*:*:*:*:*:*", "matchCriteriaId": "49C73AFB-C826-4370-BC69-AFE3C1575465" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:21.1:*:*:*:*:*:*:*", "matchCriteriaId": "1409DBBE-EADF-4237-BD2D-32EE2D28C985" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:21.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "D9311A95-4875-4ED7-A78B-62187A1D4DB7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:21.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "97E0D1F6-B4D9-4C9D-A840-AA1460B8FEF2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:21.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "9DC4F9FE-D10C-4967-A1AA-273835DE8876" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:21.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "D0FF9EDE-448B-40DF-95B9-0924D590B8DE" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:22.1:*:*:*:*:*:*:*", "matchCriteriaId": "7AA527BE-C0CD-4CA5-9713-58371D8F1F63" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:22.2:*:*:*:*:*:*:*", "matchCriteriaId": "9C0F71B7-A9CA-4B07-9550-64761ED94433" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:22.3:*:*:*:*:*:*:*", "matchCriteriaId": "3232567C-B89C-46EA-96DB-FAB08181BC86" }, { "vulnerable": true, "criteria": "cpe:2.3:o:extremenetworks:extremexos:22.4:*:*:*:*:*:*:*", "matchCriteriaId": "5A18321A-679E-4890-ACEA-CBD9231E3E18" } ] } ] } ], "references": [ { "url": "https://extremeportal.force.com/ExtrArticleDetail?n=000017765", "source": "cve@mitre.org", "tags": [ "Mitigation", "Vendor Advisory" ] } ] }