Serviio PRO 1.8 Unauthenticated Password Change via REST API
Vulnerability Description
Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the mediabrowser login password. Attackers can send specially crafted requests to the REST API endpoints to modify credentials without authentication.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-20220
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- LiquidWorm as Gjoko Krstic of Zero Science Lab
References
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5407.php
- https://blogs.securiteam.com/index.php/archives/3094
- https://www.exploit-db.com/exploits/41960/
- https://packetstormsecurity.com/files/142386
- https://cxsecurity.com/issue/WLB-2017050025
- http://www.securitylab.ru/poc/486047.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125645
- https://www.vulncheck.com/advisories/serviio-pro-unauthenticated-password-change-via-rest-api
More from Serviio
View All →Affected Vendor
Serviio
View all reports →