CVE-2017-9100
published 2017-05-21CVE-2017-9100: login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password…
PriorityP269high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
85.45%
99.7th percentile
login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password field during an admin login attempt.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-600m_firmware | — | — |
| lame_project | lame | >= 0 < 3.99.5+repack1-3ubuntu1+esm3 | 3.99.5+repack1-3ubuntu1+esm3 |
| lame_project | lame | >= 0 < 3.99.5+repack1-9ubuntu0.1~esm2 | 3.99.5+repack1-9ubuntu0.1~esm2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
lame vulnerabilities
osv·2022-08-29·CVSS 5.5
CVE-2015-9099 lame vulnerabilities
lame vulnerabilities
It was discovered that LAME incorrectly handled certain audio files. A
remote attacker could possibly use this issue to cause a denial of service. Eight
vulnerabilities (CVE-2015-9099, CVE-2015-9100, CVE-2015-9101, CVE-2017-15018,
CVE-2017-11720, CVE-2017-8419, CVE-2017-9412, CVE-2017-15045) only affected Ubuntu 14.04
ESM, two vulnerabilities (CVE-2017-9410 and CVE-2017-9411) only affected Ubuntu
16.04 ESM, and one vulnerability (CVE-2017-15019) affected both Ubuntu 14.04
ESM and Ubuntu 16.04.
GHSA
GHSA-5957-rq48-hh79: login
ghsa_unreviewed·2022-05-13
CVE-2017-9100 [HIGH] CWE-287 GHSA-5957-rq48-hh79: login
login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password field during an admin login attempt.
Red Hat
lame: Multiple vulnerabilities
vendor_redhat·2015-02-05·CVSS 5.5
CVE-2017-9411 [MEDIUM] lame: Multiple vulnerabilities
lame: Multiple vulnerabilities
[REJECTED CVE] This candidate is a duplicate of CVE-2015-9100. Note that all CVE users should reference CVE-2015-9100 instead of this candidate.
Statement: Note that all CVE users should reference CVE-2015-9100 instead of this CVE-2017-9411 candidate. Please refer to https://access.redhat.com/security/cve/CVE-2015-9100.
Package: lame (Red Hat Enterprise Linux 9) - Affected
Suricata
ET EXPLOIT HP Printer Attempted Path Traversal via PJL
suricata·2017-06-16
CVE-2017-2741 ET EXPLOIT HP Printer Attempted Path Traversal via PJL
ET EXPLOIT HP Printer Attempted Path Traversal via PJL
Rule: alert tcp any any -> $HOME_NET 9100 (msg:"ET EXPLOIT HP Printer Attempted Path Traversal via PJL"; flow:established,to_server; content:"@PJL FS"; depth:7; content:"NAME="; distance:0; pcre:"/^\s*[\x22\x27][^\x22\x27]{0,128}\x2e\x2e/Ri"; reference:url,www.tenable.com/blog/rooting-a-printer-from-security-bulletin-to-remote-code-execution; reference:cve,2017-2741; classtype:attempted-admin; sid:2024404; rev:5; metadata:created_at 2017_06_16, cve CVE_2017_2741, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_11_26, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1083, mitre_technique_name File_And_Directory_D
No public exploits indexed.
2017-05-21
Published