peter bassill · operator
$ cve CVE-2017-17833 JSON

CVE-2017-17833

9.8
CRITICAL · CVSS 3.0 · EPSS 3.8% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.76% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2018-04-23
Last modified2026-06-17

Affected (40)

VendorProduct
canonicalubuntu linux
debiandebian linux
lenovobm nextscale fan power controller
lenovocmm
lenovofan power controller
lenovoflex system fc3171 8gb san switch
lenovoflex system fc3171 8gb san switch firmware
lenovoimm1
lenovoimm2
lenovostorage n3310
lenovostorage n3310 firmware
lenovostorage n4610
lenovostorage n4610 firmware
lenovothinkserver rd340
lenovothinkserver rd340 firmware
lenovothinkserver rd350
lenovothinkserver rd350 firmware
lenovothinkserver rd350g
lenovothinkserver rd350g firmware
lenovothinkserver rd350x
lenovothinkserver rd350x firmware
lenovothinkserver rd440
lenovothinkserver rd440 firmware
lenovothinkserver rd450 firmware
lenovothinkserver rd450x
lenovothinkserver rd450x firmware
lenovothinksystem hr630x
lenovothinksystem hr630x firmware
lenovothinksystem hr650x
lenovothinksystem hr650x firmware
lenovothinksystem sr630
lenovothinksystem sr630 firmware
lenovoxclarity administrator
openslpopenslp
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation

References

→ the Explorer  ·  watch your stack  ·  NVD