CVE-2017-17743
Estado: ModificadaMedia (6.7)—
Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5.1.x before 5.1.11 allows authenticated remote attackers to escape the shell and escalate their privileges by uploading a .bashrc file containing the /bin/sh string. In some situations, authentication can be achieved via the bhu85tgb default password for the admin account.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.09%
- Percentil entre todas las CVEs puntuadas: 64
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-17743",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 6.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2018-03-22T05:29:00.237",
"references": [
{
"url": "https://securite.intrinsec.com/2018/03/19/cve-2017-17743-ucopia-shell-escape/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://securite.intrinsec.com/2018/03/19/cve-2017-17743-ucopia-shell-escape/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5.1.x before 5.1.11 allows authenticated remote attackers to escape the shell and escalate their privileges by uploading a .bashrc file containing the /bin/sh string. In some situations, authentication can be achieved via the bhu85tgb default password for the admin account."
},
{
"lang": "es",
"value": "Saneamiento de entradas indebido en el shell de administración restringido en dispositivos UCOPIA Wireless Appliance en versiones anteriores a la 4.4.20, versiones 5.0.x anteriores a la 5.0.19 y versiones 5.1.x anteriores a la 5.1.11 permite que atacantes remotos escapen el shell y escalen sus privilegios mediante la subida de un archivo .bashrc que contenga la cadena /bin/sh. En algunas situaciones, la autenticación puede lograrse mediante la contraseña por defecto bhu85tgb para la cuenta de administrador."
}
],
"lastModified": "2026-06-17T01:11:34.657",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ucopia:wireless_appliance_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64DF4E1D-4B7A-4A05-A61E-D43B63EFCC07",
"versionEndExcluding": "4.4.20"
},
{
"criteria": "cpe:2.3:o:ucopia:wireless_appliance_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1BC12478-521A-40FF-A634-9C48C4FD0613",
"versionEndExcluding": "5.0.19",
"versionStartIncluding": "5.0"
},
{
"criteria": "cpe:2.3:o:ucopia:wireless_appliance_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6231AD45-84FE-4975-9725-4F8F2A36D021",
"versionEndExcluding": "5.1.11",
"versionStartIncluding": "5.1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ucopia:wireless_appliance:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BB1C8FCD-6DE1-4356-B646-8A790A4B6DB2"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}