← Back

CVE-2017-14705

nvd nist
Published: Sep 22, 2017Modified: May 13, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted into the type parameter to the tailDateFile function in /webservices/stream/tail.php. An iToken authentication parameter is required but can be obtained by exploiting CVE-2017-14706. This affects DenyAll i-Suite LTS 5.5.0 through 5.5.12, i-Suite 5.6, Web Application Firewall 5.7, and Web Application Firewall 6.x before 6.4.1, with On Premises or AWS/Azure cloud deployments.

Affected (12)

2 products
I Suite
Web Application Firewall
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Denyall
Version 5.5.0
Version 5.5.10
Version 5.5.11
Version 5.5.12
Version 5.5.9
Version 5.6.0
Denyall
Version 5.7.0
Version 6.0.0
Version 6.1.0
Version 6.2.0
Version 6.3.0
Version 6.4.0

References (6)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory

Timeline

No history available yet.