CVE-2017-9248
Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
YesDecision
Descriptions
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.
La biblioteca Telerik.Web.UI.dll en la Interfaz de Usuario de Progress Telerik para ASP.NET AJAX anterior a la versión R2 2017 SP1 y Sitefinity anterior a la versión 10.0.6412.0, no protege apropiadamente a Telerik.Web.UI.DialogParametersEncryptionKey o MachineKey, lo que facilita para los atacantes remotos superar los mecanismos de protección criptográfica, conllevando a un perdida de MachineKey, cargas o descargas arbitrarias de archivos, XSS o un compromiso de ViewState de ASP.NET.
Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-05-28 CVE Reserved
- 2017-07-03 CVE Published
- 2019-10-23 First Exploit
- 2021-11-03 Exploited in Wild
- 2022-05-03 KEV Due Date
- 2024-07-26 EPSS Updated
- 2024-08-05 CVE Updated
CWE
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/99965 | Broken Link |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/43873 | 2024-08-05 | |
https://github.com/hlong12042/CVE-2017-9248 | 2024-07-17 | |
https://github.com/ictnamanh/CVE-2017-9248 | 2019-10-23 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | < 10.0.6412.0 Search vendor "Progress" for product "Sitefinity" and version " < 10.0.6412.0" | - |
Affected
| ||||||
Telerik Search vendor "Telerik" | Ui For Asp.net Ajax Search vendor "Telerik" for product "Ui For Asp.net Ajax" | <= 2017.2.503 Search vendor "Telerik" for product "Ui For Asp.net Ajax" and version " <= 2017.2.503" | - |
Affected
|