DNA View

⚠️ CISA Known Exploited Vulnerability

Active Threat

This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.

CVE-2017-16651

High CISA KEV
Low Medium High Critical
7.8
CVSS Score
Published: Nov 09, 2017
Last Modified: Oct 22, 2025

Vulnerability Description

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
L
Attack Complexity
L
Privileges Required
L
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
H

Known Affected Software

12 configuration(s) from 2 vendor(s)

debian_linux
Version:
7.0
CPE:
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
debian_linux
Version:
9.0
CPE:
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
webmail
Version:
1.2.2
CPE:
cpe:2.3:a:roundcube:webmail:1.2.2:*:*:*:*:*:*:*
webmail
Version:
1.3.0
CPE:
cpe:2.3:a:roundcube:webmail:1.3.0:-:*:*:*:*:*:*
webmail
Version:
1.2.0
CPE:
cpe:2.3:a:roundcube:webmail:1.2.0:-:*:*:*:*:*:*
webmail
Version:
1.3.1
CPE:
cpe:2.3:a:roundcube:webmail:1.3.1:*:*:*:*:*:*:*
webmail
Version:
1.3.2
CPE:
cpe:2.3:a:roundcube:webmail:1.3.2:*:*:*:*:*:*:*
webmail
Version:
1.2.4
CPE:
cpe:2.3:a:roundcube:webmail:1.2.4:*:*:*:*:*:*:*
webmail
Version:
1.2.3
CPE:
cpe:2.3:a:roundcube:webmail:1.2.3:*:*:*:*:*:*:*
webmail
Version:
1.2.1
CPE:
cpe:2.3:a:roundcube:webmail:1.2.1:*:*:*:*:*:*:*
webmail
Version:
1.2.6
CPE:
cpe:2.3:a:roundcube:webmail:1.2.6:*:*:*:*:*:*:*
webmail
Version:
1.2.5
CPE:
cpe:2.3:a:roundcube:webmail:1.2.5:*:*:*:*:*:*:*
This vulnerability affects 12 software configuration(s). Ensure you patch all affected systems.

References & Resources

Severity Details

7.8
out of 10.0
High

CISA KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog

Key Information

Published Date
November 09, 2017