⚠️ CISA Known Exploited Vulnerability
Active ThreatThis vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.
CVE-2017-16651
High CISA KEVVulnerability Description
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Known Affected Software
12 configuration(s) from 2 vendor(s)
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:1.3.0:-:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:1.2.0:-:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:1.2.5:*:*:*:*:*:*:*
References & Resources
-
http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclosure.htmlcve@mitre.org Exploit Third Party Advisory VDB Entry
-
http://www.securityfocus.com/bid/101793cve@mitre.org Third Party Advisory VDB Entry
-
https://github.com/roundcube/roundcubemail/issues/6026cve@mitre.org Issue Tracking Patch Third Party Advisory
-
https://github.com/roundcube/roundcubemail/releases/tag/1.1.10cve@mitre.org Issue Tracking Release Notes Third Party Advisory
-
https://github.com/roundcube/roundcubemail/releases/tag/1.2.7cve@mitre.org Issue Tracking Release Notes Third Party Advisory
-
https://github.com/roundcube/roundcubemail/releases/tag/1.3.3cve@mitre.org Issue Tracking Release Notes Third Party Advisory
-
https://lists.debian.org/debian-lts-announce/2017/11/msg00039.htmlcve@mitre.org Mailing List Third Party Advisory
-
https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10cve@mitre.org Issue Tracking Vendor Advisory
-
https://www.debian.org/security/2017/dsa-4030cve@mitre.org Issue Tracking Third Party Advisory
-
http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclosure.htmlaf854a3a-2127-422b-91ae-364da2661108 Exploit Third Party Advisory VDB Entry
-
http://www.securityfocus.com/bid/101793af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory VDB Entry
-
https://github.com/roundcube/roundcubemail/issues/6026af854a3a-2127-422b-91ae-364da2661108 Issue Tracking Patch Third Party Advisory
-
https://github.com/roundcube/roundcubemail/releases/tag/1.1.10af854a3a-2127-422b-91ae-364da2661108 Issue Tracking Release Notes Third Party Advisory
-
https://github.com/roundcube/roundcubemail/releases/tag/1.2.7af854a3a-2127-422b-91ae-364da2661108 Issue Tracking Release Notes Third Party Advisory
-
https://github.com/roundcube/roundcubemail/releases/tag/1.3.3af854a3a-2127-422b-91ae-364da2661108 Issue Tracking Release Notes Third Party Advisory
-
https://lists.debian.org/debian-lts-announce/2017/11/msg00039.htmlaf854a3a-2127-422b-91ae-364da2661108 Mailing List Third Party Advisory
-
https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10af854a3a-2127-422b-91ae-364da2661108 Issue Tracking Vendor Advisory
-
https://www.debian.org/security/2017/dsa-4030af854a3a-2127-422b-91ae-364da2661108 Issue Tracking Third Party Advisory
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-16651134c704f-9b21-4f2e-91b3-4a467353bcc0
Severity Details
CISA KEV Status
Listed in CISA's Known Exploited Vulnerabilities catalog
Key Information
- Published Date
- November 09, 2017
