Serviio PRO 1.8 Unauthenticated Password Change via REST API
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the mediabrowser login password. Attackers can send specially crafted requests to the REST API endpoints to modify credentials without authentication.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Serviio · Serviio PROReferences
https://blogs.securiteam.com/index.php/archives/3094https://cxsecurity.com/issue/WLB-2017050025https://exchange.xforce.ibmcloud.com/vulnerabilities/125645https://packetstormsecurity.com/files/142386https://www.exploit-db.com/exploits/41960/https://www.vulncheck.com/advisories/serviio-pro-unauthenticated-password-change-via-rest-apihttps://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5407.phphttp://www.securitylab.ru/poc/486047.php