LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2017-20220

Published
CVSS7.5
Severityhigh
WeaknessCWE-306
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the mediabrowser login password. Attackers can send specially crafted requests to the REST API endpoints to modify credentials without authentication.

References

← Back to the CVE Tracker

Our coverage of CVE-2017-20220

No stories yet. This page updates automatically when we publish reporting that references CVE-2017-20220.