EXPOSURES › CVE-2017-17562
CVE-2017-17562
HIGH ⌖ ON CISA KEV · EXPLOITEDEmbedthis GoAhead before 3.6.5 allows remote code execution when CGI is enabled and a CGI program is dynamically linked.
This unpatched RCE vulnerability in Embedthis GoAhead is actively exploited in the wild, posing a severe risk to any system running this software with CGI enabled. DIB organizations must immediately patch this CVE to prevent attackers from executing arbitrary code, which could lead to data breaches, system compromise, and compliance violations under NIST 800-171. The fact that it is in the KEV catalog confirms its active exploitation, making it a critical priority for remediation.
Shame score — An actively exploited RCE vulnerability in a widely used web server software that remained unpatched long enough to be added to the KEV catalog, demonstrating severe negligence in patch management and software maintenance.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.