CVE-2017-16539 describes a vulnerability in Docker Moby through version 17.03.2-ce, where the DefaultLinuxSpec function fails to block /proc/scsi pathnames. This oversight allows attackers with Docker container access to trigger data loss on systems running certain older Linux kernels by writing a "scsi remove-single-device" command to /proc/scsi/scsi, an issue dubbed SCSI MICDROP. The vulnerability has a CVSS score of 5.9 (Medium), indicating a network-based attack with high complexity and a high impact on availability, though confidentiality and integrity are not affected. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, aligning with the typical low engagement for most vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 17.03.2CPE matchmatch criteria | cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.