CVE-2018-17431
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 84%
from disclosure to weapon0 days
Published on NVDJan 29
1st PoCDec 8
VulnCheck+1903d
exploitation probability
84%top 1% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.
Affected products
n/a · n/apublic PoCs found — 5
exploitdbwww.exploit-db.com/exploits/48825unverifiedgithubgithub.com/Fadavvi/CVE-2018-17431-PoC★ 2githubgithub.com/sanan2004/CVE-2018-17431-Comodo★ 0cve_referencepacketstormsecurity.com/files/159246/Comodo-Unified-Threat-Management-Web-Console-2.7.0-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/344483d07f18unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/159246/Comodo-Unified-Threat-Management-Web-Console-2.7.0-Remote-Code-Execution.htmlhttps://drive.google.com/file/d/0BzFJhNQNHcoTbndsUmNjVWNGYWNJaWxYcWNyS2ZDajluTDFz/viewhttps://github.com/Fadavvi/CVE-2018-17431-PoC#confirmation-than-bug-exist-2018-09-25-ticket-id-xwr-503-79437