CVE-2017-5738
published 2017-11-16CVE-2017-5738: Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 allows an attacker with network access to…
PriorityP343critical9.1CVSS 3.0
AVNACLPRNUINSUCHINAH
EPSS
1.53%
72.0th percentile
Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 allows an attacker with network access to cause a denial of service and/or information disclosure.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | unite | — | — |
| intel | unite | — | — |
| intel | unite | — | — |
| intel_corporation | unite_app | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-76j8-5m68-735c: Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3
ghsa_unreviewed·2022-05-13
CVE-2017-5738 [CRITICAL] CWE-200 GHSA-76j8-5m68-735c: Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3
Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 allows an attacker with network access to cause a denial of service and/or information disclosure.
Red Hat
bind: Improper handling of configuration allows all clients to perform recursive queries
vendor_redhat·2018-06-12·CVSS 5.3
CVE-2018-5738 [MEDIUM] CWE-284 bind: Improper handling of configuration allows all clients to perform recursive queries
bind: Improper handling of configuration allows all clients to perform recursive queries
Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not specified a value for the "allow-recursion" setting, it SHOULD default to one of the following: none, if "recursion no;" is set in named.conf; a value inherited from the "allow-query-cache" or "allow-query" settings IF "recursion yes;" (the default for that setting) AND match lists are explicitly set for "allow-query-cache" or "allow-query" (see the BIND9 Administrative Reference Manual section 6.2 for more details); or the intend
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-11-16
Published