← back
CVE-2017-11610observed exploitation

CVE-2017-11610

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 87%
from disclosure to weapon33 days
Published on NVDAug 23
1st PoC+33d
metasploitJul 19
VulnCheck+1324d
exploitation probability
87%top 1% of all CVEs
observed exploitation
yesVulnCheck
8 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
2 products
Red Hat Ceph Storage 1.3 · Red Hat Ceph Storage 2
no_fix_planned: Will not fix
Fixed
1 product (18 components)
CloudForms Management Engine 5.8
Not affected
1 product — because the vulnerable code is not present in the product
Red Hat Mobile Application Platform 4
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.