peter bassill · operator
$ cve CVE-2017-5123 JSON

CVE-2017-5123 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 3.7% (pctl 89)

Patch early

A public exploit exists.

Description

Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS3.71% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2021-11-02
Last modified2026-06-17

Affected (16)

VendorProduct
linuxlinux kernel
netappcloud backup
netapph300e
netapph300e firmware
netapph300s
netapph300s firmware
netapph410s
netapph410s firmware
netapph500e
netapph500e firmware
netapph500s
netapph500s firmware
netapph700e
netapph700e firmware
netapph700s
netapph700s firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD