CVE-2017-7546
9.8
CRITICAL · CVSS 3.0 · EPSS 61.6% (pctl 99)
Patch early
EPSS 61.6% — above the 10% action threshold.
Description
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 61.57% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-08-16 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| debian | debian linux |
| postgresql | postgresql |
References
- http://www.debian.org/security/2017/dsa-3935
- http://www.debian.org/security/2017/dsa-3936
- http://www.securityfocus.com/bid/100278
- http://www.securitytracker.com/id/1039142
- https://access.redhat.com/errata/RHSA-2017:2677
- https://access.redhat.com/errata/RHSA-2017:2678
- https://access.redhat.com/errata/RHSA-2017:2728
- https://access.redhat.com/errata/RHSA-2017:2860
- https://security.gentoo.org/glsa/201710-06
- https://www.postgresql.org/about/news/1772/
- http://www.debian.org/security/2017/dsa-3935
- http://www.debian.org/security/2017/dsa-3936
- http://www.securityfocus.com/bid/100278
- http://www.securitytracker.com/id/1039142
- https://access.redhat.com/errata/RHSA-2017:2677
- https://access.redhat.com/errata/RHSA-2017:2678
- https://access.redhat.com/errata/RHSA-2017:2728
- https://access.redhat.com/errata/RHSA-2017:2860
- https://security.gentoo.org/glsa/201710-06
- https://www.postgresql.org/about/news/1772/
→ the Explorer · watch your stack · NVD