HIGH

CVE-2018-7171

CVSS v3

7.5

HIGH

EPSS Score

48.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all.

Technical details

Published
3/30/2018

Frequently asked questions

What is CVE-2018-7171?

Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all.

Is CVE-2018-7171 actively exploited?

Active exploitation of CVE-2018-7171 has not been confirmed. The EPSS score is 48.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-7171?

CVE-2018-7171 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2018-7171 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.