CVE-2017-11165
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 64%
from disclosure to weapon0 days
Published on NVDJul 12
1st PoCJul 11
exploitation probability
64%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/42313unverifiedcve_referencepacketstormsecurity.com/files/143328/DataTaker-DT80-dEX-1.50.012-Sensitive-Configuration-Exposure.htmlunverifiedcve_referencewww.exploit-db.com/exploits/42313/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.