CVE-2017-3222

CRITICAL

Inmarsat AmosConnect 8 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

Hard-coded credentials in AmosConnect 8 allow remote attackers to gain full administrative privileges, including the ability to execute commands on the Microsoft Windows host platform with SYSTEM privileges by abusing AmosConnect Task Manager.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99899
Third Party Advisory x_refsource_misc
https://twitter.com/mkolsek/status/923988845783322625
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/586501

Scores

CVSS v3 9.8
EPSS 0.0741
EPSS Percentile 93.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (11)
inmarsat/amosconnect 8.0
inmarsat/amosconnect 8.0.1
inmarsat/amosconnect 8.0.2
inmarsat/amosconnect 8.2.0
inmarsat/amosconnect 8.2.1
inmarsat/amosconnect 8.2.2
inmarsat/amosconnect 8.3.0
inmarsat/amosconnect 8.3.1
inmarsat/amosconnect 8.4.0
inmarsat/amosconnect 8.4.0.1
... and 1 more
Published Jul 22, 2017
Tracked Since Feb 18, 2026