CVE-2017-9812 is a high-severity vulnerability affecting Kaspersky Anti-Virus for Linux File Server versions prior to 8.0.4.312. It allows an unauthenticated attacker to read arbitrary files with kluser privileges by manipulating the reportId parameter in the getReportStatus action method of the web interface. This remote arbitrary file read vulnerability has a CVSS score of 7.5, indicating a high impact on confidentiality with no integrity or availability impact. While not listed on CISA KEV, public exploit code exists on ExploitDB, and it has received some community discussion and media coverage, suggesting it is a known and potentially exploitable flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.0.3.297CPE matchmatch criteria | cpe:2.3:a:kaspersky:anti-virus_for_linux_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.