CVE-2017-17406 is a critical remote code execution vulnerability affecting Netgain Enterprise Manager, specifically due to improper validation of user-supplied data within an exposed RMI registry. This allows unauthenticated attackers to execute arbitrary code by deserializing untrusted data. With a CVSS score of 9.8, it presents a severe risk, enabling full compromise of confidentiality, integrity, and availability without user interaction. Despite its high severity and EPSS score, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, and it shows no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.2.766CPE matchmatch criteria | cpe:2.3:a:netgain-systems:enterprise_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] NetGain Enterprise Manager Multiple Remote Vulnerabilities
Jan 29, 2018[R1] NetGain Enterprise Manager Multiple Remote Vulnerabilities
Jan 29, 2018NetGain Enterprise Manager Multiple Remote Vulnerabilities
Jan 29, 2018