peter bassill · operator
$ cve CVE-2017-7546 JSON

CVE-2017-7546

9.8
CRITICAL · CVSS 3.0 · EPSS 61.6% (pctl 99)

Patch early

EPSS 61.6% — above the 10% action threshold.

Description

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS61.57% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2017-08-16
Last modified2026-06-17

Affected (2)

VendorProduct
debiandebian linux
postgresqlpostgresql

References

→ the Explorer  ·  watch your stack  ·  NVD