CVE-2017-17415 is a critical SQL injection vulnerability affecting Quest NetVault Backup 11.3.0.12, allowing unauthenticated remote attackers to execute arbitrary code. The flaw stems from insufficient validation of user-supplied input in NVBUPhaseStatus Count method requests, leading to arbitrary code execution in the context of the underlying database. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise potential (Confidentiality, Integrity, Availability). Despite its severity, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in CISA's KEV catalog, and there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.3.0.12CPE matchmatch criteria | cpe:2.3:a:quest:netvault_backup:11.3.0.12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.