« Volver al listado

CVE-2017-15883

Estado: ModificadaCrítica (9.8)—

Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-15883",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-01-08T19:29:00.953",
  "references": [
    {
      "url": "https://knowledgebase.progress.com/articles/Article/Sitefinity-Security-Advisory-for-cryptographic-vulnerability-CVE-2017-15883",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.mnemonic.no/news/2017/vulnerability-finding-sitefinity-cms/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://knowledgebase.progress.com/articles/Article/Sitefinity-Security-Advisory-for-cryptographic-vulnerability-CVE-2017-15883",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.mnemonic.no/news/2017/vulnerability-finding-sitefinity-cms/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography."
    },
    {
      "lang": "es",
      "value": "Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x y 10.x permite que los atacantes remotos omitan la autenticación y que provoquen una denegación de servicio (DoS) en consecuencia en las páginas con carga balanceada o obtengan privilegios mediante vectores relacionados con una criptografía débil."
    }
  ],
  "lastModified": "2026-06-17T01:08:25.870",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E7D51DC-4323-4688-909A-F7A91606AAA9"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BA4201A-5E74-4175-8CA7-14E1FF9C919F"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1093AEA4-6171-4888-B459-4E556F795647"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9FCC0A55-CB11-4E94-8E47-0A01190B3306"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0898F18C-75C2-49E4-A0D5-7F8A621BCDF0"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6B5D7A1-55C3-4019-B987-3DFB0890A016"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:6.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F90C068-F46A-404E-B8C0-61C66E3490E3"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7EC9C199-4B1D-475B-A230-382B79FF2E5F"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5879E989-5FA5-4B7C-B408-D28BF9A6E475"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A429147-D26F-4D00-82F8-0AB38787F058"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3894214-0F21-4B1A-86B7-5C1C959CEBB2"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5703FDB2-89F3-4A4D-8CE1-DAB5410364C0"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9765DA21-E412-4531-8414-5E9909DD7C64"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8A3612F-4F13-496F-BCB7-443B28F83757"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B539481B-721D-4711-8547-549D6BF4EFE8"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E118E651-D5EA-4A3C-95D3-ABE7A7A410F8"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F361531-8E0F-42AB-8ECF-541A201438E6"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44C5BD02-D8AA-4525-BACA-B4C6C0563A18"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EF7E946-EBF1-45A9-99C7-AF38E5845CE5"
            },
            {
              "criteria": "cpe:2.3:a:progress:sitefinity:10.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "252F8F5C-C395-40F6-808C-F278EB21E5A0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}