Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-7529

59
FAUCET Score

CVE-2017-7529 is an integer overflow vulnerability in the Nginx range filter module, affecting Nginx versions 0.5.6 through 1.13.2, as well as products integrating these Nginx versions such as Apple and Puppet Enterprise. This vulnerability carries a high severity CVSS score of 7.5, indicating it can be exploited remotely with low attack complexity, potentially leading to the disclosure of sensitive information. While it has a very high EPSS score suggesting exploitability, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on CISA's KEV catalog. Community discussion and media coverage are minimal, with only one mention and one article identified.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.5.6, <= 1.12.1CPE matchmatch criteria
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
>= 1.13.0, <= 1.13.2CPE matchmatch criteria
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
< 2016.4.7CPE matchmatch criteria
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*
>= 2017.1.0, <= 2017.1.1CPE matchmatch criteria
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*
>= 2017.2.1, <= 2017.2.3CPE matchmatch criteria
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
62.60%
Probability of exploitation in next 30 days
EPSS Percentile
99.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.6260 is in the 98th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

dahuapatch availablevia llm_extracted
Fixed in: 1.12.1+
View patch
dfinitypatch availablevia llm_extracted
Fixed in: 1.13.3
View patch
jfrogpatch availablevia llm_extracted
Fixed in: 1.13.3
View patch
liferaypatch availablevia llm_extracted
Fixed in: 1.12.1
View patch
netgearpatch availablevia llm_extracted
Fixed in: 1.13.3+, 1.12.1+
View patch
opensshpatch availablevia llm_extracted
Fixed in: 1.13.3
View patch
power_bipatch availablevia llm_extracted
Fixed in: 1.12.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-nginx110-nginx-1:1.10.2-8.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSFixed in: rh-nginx110-nginx-1:1.10.2-8.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSFixed in: rh-nginx110-nginx-1:1.10.2-8.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-nginx110-nginx-1:1.10.2-8.el7
View patch
terraformpatch availablevia llm_extracted
Fixed in: 1.13.3
View patch
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-nginx18-nginx

Vendor Advisories (9)

redhatCVE-2017-7529Low

nginx: Integer overflow in nginx range filter module leading to memory disclosure

Jul 11, 2017
opensshllm-openssh-c2fa0c55507287deMEDIUM

Integer overflow in the range filter

Jan 1, 2017
dfinityllm-dfinity-c535a60126bcf3f7MEDIUM

Integer overflow in the range filter

Jan 1, 2017
power_billm-power_bi-3e6bac04d16b9422MEDIUM

Integer overflow in the range filter

Jan 1, 2017
liferayllm-liferay-45f38ae0ed085048MEDIUM

Integer overflow in the range filter

Jan 1, 2017
jfrogllm-jfrog-a4ef3b24eb5ea895MEDIUM

Integer overflow in the range filter

Jan 1, 2017
dahuallm-dahua-aece19b1ca8c84e8MEDIUM

Integer overflow in the range filter

terraformllm-terraform-edd124420c8ee123MEDIUM

Integer overflow in the range filter

netgearllm-netgear-b927b4c267097cefMEDIUM

Integer overflow in the range filter

References

mailman.nginx.org / pipermail/nginx-announce/2017/000200.html
Vendor Advisory
access.redhat.com / errata/RHSA-2017:2538
Third Party Advisory
seclists.org / fulldisclosure/2021/Sep/36
Mailing ListThird Party Advisory
puppet.com / security/cve/cve-2017-7529
Third Party Advisory
support.apple.com / kb/HT212818
Third Party Advisory
securityfocus.com / bid/99534
Third Party AdvisoryVDB Entry
securitytracker.com / id/1039238
Third Party AdvisoryVDB Entry