← back
CVE-2019-17571

CVE-2019-17571

CVSS 9.8 CRITICALEPSS 69.1%CWE-502
Vexday Risk Score
60Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 69.1%KEV nãoPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
20 Dec 2019Published on NVD
25 Dec 2019Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →