CVE-2017-17482 is a buffer overflow vulnerability affecting OpenVMS versions through V8.4-2L2 on Alpha, V8.4-2L1 on IA64, and VAX/VMS 4.0 and later, regardless of vendor. A local, non-privileged attacker can exploit this by entering a crafted DCL command line, leading to local privilege escalation on VAX and Alpha systems, and potentially a process crash on IA64. With a CVSS score of 7.8 (High), this vulnerability has low attack complexity and requires no user interaction, allowing for high impact to confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.4-2l1CPE matchmatch criteria | cpe:2.3:o:hp:openvms:*:*:*:*:alpha:*:*:* | ||
<= 8.4-2l1CPE matchmatch criteria | cpe:2.3:o:hp:openvms:*:*:*:*:ia64:*:*:* | ||
>= 4.0CPE matchmatch criteria | cpe:2.3:o:hp:openvms:*:*:*:*:vax:*:*:* | ||
>= 4.0CPE matchmatch criteria | cpe:2.3:o:hp:openvms:*:*:*:*:vms:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.