Skip to content
COOEY

EXPOSURES › CVE-2017-17562

CVE-2017-17562

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-17562 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Embedthis GoAhead before 3.6.5 allows remote code execution when CGI is enabled and a CGI program is dynamically linked.

This unpatched RCE vulnerability in Embedthis GoAhead is actively exploited in the wild, posing a severe risk to any system running this software with CGI enabled. DIB organizations must immediately patch this CVE to prevent attackers from executing arbitrary code, which could lead to data breaches, system compromise, and compliance violations under NIST 800-171. The fact that it is in the KEV catalog confirms its active exploitation, making it a critical priority for remediation.

Shame score — An actively exploited RCE vulnerability in a widely used web server software that remained unpatched long enough to be added to the KEV catalog, demonstrating severe negligence in patch management and software maintenance.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.