CVE-2017-15400
Estado: ModificadaAlta (7.8)—
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.86%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-93
Referencias
- https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.html
- https://crbug.com/777215
- https://security.gentoo.org/glsa/201908-08
- https://www.debian.org/security/2018/dsa-4243
- https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.html
- https://crbug.com/777215
- https://security.gentoo.org/glsa/201908-08
- https://www.debian.org/security/2018/dsa-4243
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-15400",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "chrome-cve-admin@google.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Google Chrome OS prior to 62.0.3202.74",
"versions": [
{
"status": "affected",
"version": "Google Chrome OS prior to 62.0.3202.74"
}
]
}
]
}
],
"published": "2018-02-07T23:29:00.937",
"references": [
{
"url": "https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.html",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://crbug.com/777215",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://security.gentoo.org/glsa/201908-08",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://www.debian.org/security/2018/dsa-4243",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-chrome-os_27.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://crbug.com/777215",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/201908-08",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.debian.org/security/2018/dsa-4243",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-93"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue."
},
{
"lang": "es",
"value": "La restricción insuficiente de filtros IPP en CUPS en Google Chrome OS, en versiones anteriores a la 62.0.3202.74, permite que un atacante remoto ejecute un comando con los mismos privilegios que el demonio cups mediante un archivo PPD manipulado. Esto también se conoce como problema CRLF zeroconfig de impresora."
}
],
"lastModified": "2026-06-17T01:07:45.947",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87004649-1263-4704-A4EE-B3132BFC08FD",
"versionEndExcluding": "62.0.3202.74"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "chrome-cve-admin@google.com"
}