CVE-2017-9385
An issue was discovered on Vera Veralite 1.7.481 devices. The device has an additional OpenWRT interface in addition to the standard web interface which allows the highest privileges a user can obtain on the device. This web interface uses root as the username and the password in the /etc/cmh/cmh.conf file which can be extracted by an attacker using a directory traversal attack, and then log in to the device with the highest privileges.
- Affected products
- Openwrt, Vera Veralite
- Getvera Veraedge Firmware
- ≤ 1.7.19
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 3.5% (88th percentile)
- Weakness
- CWE-255
- NVD status
- Modified
- Published
- 2019-06-17
CVE-2017-9385 at NVD
No indexed exploits for CVE-2017-9385 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2017-9385 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.