SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-17675

Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs.

MEDIUM 5.3EPSS 0.87%

Does this matter?

Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.

Description

BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.87% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-532
Affected
bmc/remedy mid-tier
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.