CVE-2017-11509 allows an authenticated remote attacker to execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by crafting and executing a malicious SQL statement. This vulnerability is rated as HIGH severity (CVSS 8.8), indicating a low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it is not listed on the KEV catalog, its high FAUCET Risk Score of 85/100 and above-average EPSS score suggest a notable risk. There is currently no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5.7CPE matchmatch criteria | cpe:2.3:a:firebirdsql:firebird:2.5.7:*:*:*:*:*:*:* | ||
3.0.2CPE matchmatch criteria | cpe:2.3:a:firebirdsql:firebird:3.0.2:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Firebird fbudf Module Authenticated Remote Code Execution
Nov 21, 2017[R1] Firebird fbudf Module Authenticated Remote Code Execution
Nov 21, 2017firebird: Firebird fbudf Module Authenticated Remote Code Execution
Nov 21, 2017Firebird fbudf Module Authenticated Remote Code Execution
Nov 21, 2017