peter bassill · operator
$ cve CVE-2017-18001 JSON

CVE-2017-18001 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 13.8% (pctl 96)

Patch early

A public exploit exists.

Description

Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS13.82% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploityes
Published2017-12-31
Last modified2026-06-17

Affected (1)

VendorProduct
trustwavesecure web gateway

Public exploits

SourceTitleDate
exploit-dbTrustwave SWG 11.8.0.27 - SSH Unauthorized Access2017-12-26

References

→ the Explorer  ·  watch your stack  ·  NVD