CVE-2017-17833
9.8
CRITICAL · CVSS 3.0 · EPSS 3.8% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.76% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-04-23 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| lenovo | bm nextscale fan power controller |
| lenovo | cmm |
| lenovo | fan power controller |
| lenovo | flex system fc3171 8gb san switch |
| lenovo | flex system fc3171 8gb san switch firmware |
| lenovo | imm1 |
| lenovo | imm2 |
| lenovo | storage n3310 |
| lenovo | storage n3310 firmware |
| lenovo | storage n4610 |
| lenovo | storage n4610 firmware |
| lenovo | thinkserver rd340 |
| lenovo | thinkserver rd340 firmware |
| lenovo | thinkserver rd350 |
| lenovo | thinkserver rd350 firmware |
| lenovo | thinkserver rd350g |
| lenovo | thinkserver rd350g firmware |
| lenovo | thinkserver rd350x |
| lenovo | thinkserver rd350x firmware |
| lenovo | thinkserver rd440 |
| lenovo | thinkserver rd440 firmware |
| lenovo | thinkserver rd450 firmware |
| lenovo | thinkserver rd450x |
| lenovo | thinkserver rd450x firmware |
| lenovo | thinksystem hr630x |
| lenovo | thinksystem hr630x firmware |
| lenovo | thinksystem hr650x |
| lenovo | thinksystem hr650x firmware |
| lenovo | thinksystem sr630 |
| lenovo | thinksystem sr630 firmware |
| lenovo | xclarity administrator |
| openslp | openslp |
| redhat | enterprise linux desktop |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server eus |
| redhat | enterprise linux server tus |
| redhat | enterprise linux workstation |
References
- http://support.lenovo.com/us/en/solutions/LEN-18247
- https://access.redhat.com/errata/RHSA-2018:2240
- https://access.redhat.com/errata/RHSA-2018:2308
- https://lists.debian.org/debian-lts-announce/2018/04/msg00029.html
- https://security.gentoo.org/glsa/202005-12
- https://sourceforge.net/p/openslp/mercurial/ci/151f07745901cbdba6e00e4889561b4083250da1/
- https://usn.ubuntu.com/3708-1/
- http://support.lenovo.com/us/en/solutions/LEN-18247
- https://access.redhat.com/errata/RHSA-2018:2240
- https://access.redhat.com/errata/RHSA-2018:2308
- https://lists.debian.org/debian-lts-announce/2018/04/msg00029.html
- https://security.gentoo.org/glsa/202005-12
- https://sourceforge.net/p/openslp/mercurial/ci/151f07745901cbdba6e00e4889561b4083250da1/
- https://usn.ubuntu.com/3708-1/
→ the Explorer · watch your stack · NVD