Published on June 11th, 2019 📆 | 5845 Views ⚑
0Starry Station Webserver Access-Control-Allow-Origin privilege escalation
CVSS Meta Temp Score | Current Exploit Price (β) |
---|---|
5.5 | $0-$5k |
A vulnerability, which was classified as critical, has been found in Starry Station (affected version not known). Affected by this issue is an unknown part of the component Webserver. The manipulation of the argument Access-Control-Allow-Origin
as part of a Header leads to a privilege escalation vulnerability. Using CWE to declare the problem leads to CWE-269. Impacted is confidentiality, integrity, and availability.
The weakness was shared 06/11/2019 as mailinglist post (Bugtraq). The advisory is shared for download at seclists.org. This vulnerability is handled as CVE-2017-13717 since 08/28/2017. There are known technical details, but no exploit is available. The current price for an exploit might be approx. USD $0-$5k (estimation calculated on 06/11/2019).
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.
The entry 136245 is related to this item.
Vendor
Name
VulDB Meta Base Score: 5.5
VulDB Meta Temp Score: 5.5
VulDB Base Score: β5.5
VulDB Temp Score: β5.5
VulDB Vector: π
VulDB Reliability: π
VulDB Base Score: π
VulDB Temp Score: π
VulDB Reliability: π
Class: Privilege escalation (CWE-269)
Local: Yes
Remote: No
Availability: π
Status: Not defined
Price Prediction: π
Current Price Estimation: π
0-Day | unlock | unlock | unlock | unlock |
---|---|---|---|---|
Today | unlock | unlock | unlock | unlock |
Threat Intelligence
Threat: π
Adversaries: π
Geopolitics: π
Economy: π
Predictions: π
Remediation: πRecommended: no mitigation known
0-Day Time: π
08/28/2017 CVE assigned
06/11/2019 Advisory disclosed
06/11/2019 VulDB entry created
06/11/2019 VulDB last updateAdvisory: seclists.org
CVE: CVE-2017-13717 (π)
See also: π
Created: 06/11/2019 06:56 AM
Complete: π
Download the whitepaper to learn more about our service!
https://vuldb.com/?id.136244
Gloss