Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-7555

33
FAUCET Score

CVE-2017-7555 describes a critical heap-based buffer overflow vulnerability in Augeas versions up to and including 1.8.0, stemming from improper handling of escaped strings. This flaw allows an unauthenticated attacker to remotely trigger a crash or potentially achieve arbitrary code execution by sending specially crafted strings to applications utilizing Augeas. Despite its CVSS score of 9.8 (CRITICAL) and high FAUCET Risk Score, there is currently no public exploit code available, and it shows minimal community discussion or media coverage, indicating a low likelihood of active exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.8.0CPE matchmatch criteria
cpe:2.3:a:augeas:augeas:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
5.00%
Probability of exploitation in next 30 days
EPSS Percentile
91.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0500 is in the 85th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Telco Extended Update SupportFixed in: augeas-0:1.4.0-2.el7_3.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: augeas-0:1.4.0-2.el7_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Update Services for SAP SolutionsFixed in: augeas-0:1.4.0-2.el7_3.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Advanced Update SupportFixed in: augeas-0:1.4.0-2.el7_3.1
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: rhev-hypervisor
redhatend of lifevia redhat_api
Product: Red Hat Storage 3Fixed in: augeas
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: augeas
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 6 (Juno) InstallerFixed in: augeas

Vendor Advisories (1)

redhatCVE-2017-7555Important

augeas: Improper handling of escaped strings leading to memory corruption

Aug 17, 2017

References

access.redhat.com / errata/RHSA-2017:2788
access.redhat.com / errata/RHSA-2019:2403
github.com / hercules-team/augeas/pull/480
Third Party Advisory
puppet.com / security/cve/cve-2017-7555
debian.org / security/2017/dsa-3949
securityfocus.com / bid/100378
Third Party AdvisoryVDB Entry