CVE-2017-14706
DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservices/download/index.php, and then reading the iToken field in the reply.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 28.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservices/download/index.php, and then reading the iToken field in the reply. This affects DenyAll i-Suite LTS 5.5.0 through 5.5.12, i-Suite 5.6, Web Application Firewall 5.7, and Web Application Firewall 6.x before 6.4.1, with On Premises or AWS/Azure cloud deployments.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 28.24% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- denyall/i-suite · denyall/web application firewall
- Source
- cve@mitre.org
References
- https://github.com/rapid7/metasploit-framework/pull/8980Exploit, Third Party Advisory
- https://pentest.blog/advisory-denyall-web-application-firewall-unauthenticated-remote-code-execution/Exploit, Technical Description, Third Party Advisory
- https://www.denyall.com/blog/advisories/advisory-unauthenticated-remote-code-execution-denyall-web-application-firewall/Vendor Advisory
- https://github.com/rapid7/metasploit-framework/pull/8980Exploit, Third Party Advisory
- https://pentest.blog/advisory-denyall-web-application-firewall-unauthenticated-remote-code-execution/Exploit, Technical Description, Third Party Advisory
- https://www.denyall.com/blog/advisories/advisory-unauthenticated-remote-code-execution-denyall-web-application-firewall/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.