CVE-2017-20220 identifies an improper access control vulnerability within the Configuration REST API of Serviio PRO 1.8. This flaw permits unauthenticated attackers to send specially crafted requests, enabling them to change the mediabrowser login password. Rated with a CVSS score of 7.5 (HIGH), the vulnerability has a network attack vector and low attack complexity, requiring no authentication or user interaction. Successful exploitation results in a high confidentiality impact by compromising system login credentials. Although not present on the CISA KEV catalog, exploit code for this vulnerability has been confirmed to exist via Packetstorm, and it is currently on the Hot List, indicating active tracking.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Serviio | Serviio PRO | 1.6.1, 1.7.0, 1.7.1, 1.8.0.0 PROCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.