CVE-2017-20022 is an information disclosure vulnerability affecting Solare Solar-Log versions 2.8.4-56 and 3.5.2-85. This flaw allows an unauthenticated, remote attacker to access sensitive information due to an unspecified weakness. With a CVSS score of 7.5 (HIGH), it presents a significant risk, requiring no user interaction or complex attack techniques. While no public exploit code or active exploitation has been observed, and community discussion is minimal, upgrading to Solar-Log version 3.5.3-86 is strongly recommended to mitigate this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.8.4-56CPE matchmatch criteria | cpe:2.3:o:solar-log:solar-log_250_firmware:2.8.4-56:*:*:*:*:*:*:* | ||
3.5.2-85CPE matchmatch criteria | cpe:2.3:o:solar-log:solar-log_250_firmware:3.5.2-85:*:*:*:*:*:*:* | ||
2.8.4-56CPE matchmatch criteria | cpe:2.3:o:solar-log:solar-log_300_firmware:2.8.4-56:*:*:*:*:*:*:* | ||
3.5.2-85CPE matchmatch criteria | cpe:2.3:o:solar-log:solar-log_300_firmware:3.5.2-85:*:*:*:*:*:*:* | ||
2.8.4-56CPE matchmatch criteria | cpe:2.3:o:solar-log:solar-log_500_firmware:2.8.4-56:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.