CRITICAL

CVE-2016-11017

CVSS v3

9.8

CRITICAL

EPSS Score

19.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login failure field). This is fixed in 16.6.

Technical details

Published
1/6/2020

Frequently asked questions

What is CVE-2016-11017?

The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login failure field). This is fixed in 16.6.

Is CVE-2016-11017 actively exploited?

Active exploitation of CVE-2016-11017 has not been confirmed. The EPSS score is 19.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2016-11017?

CVE-2016-11017 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2016-11017 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.