« Volver al listado

CVE-2017-15293

Estado: ModificadaCrítica (9.8)—

Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-15293",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-10-16T16:29:00.917",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/100713",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://erpscan.io/advisories/erpscan-17-032-sap-pos-missing-authentication-xpressserver/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://erpscan.io/research/hacking-sap-pos/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/100713",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://erpscan.io/advisories/erpscan-17-032-sap-pos-missing-authentication-xpressserver/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://erpscan.io/research/hacking-sap-pos/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064."
    },
    {
      "lang": "es",
      "value": "Xpress Server en SAP POS no requiere autenticación para las operaciones de lectura y borrado de archivos, apagado del demonio, operaciones de lectura del terminal, o ciertos ataques sobre credenciales. Esto corresponde con SAP Security Note 2520064."
    }
  ],
  "lastModified": "2026-06-17T01:07:32.117",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:point_of_sale_xpress_server:1020:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B5C1170-F8AD-4D69-976B-AC4A73095E2A"
            },
            {
              "criteria": "cpe:2.3:a:sap:point_of_sale_xpress_server:1030:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "323D5C2D-1F41-4DBA-A718-43CE661951CC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}