CVE-2017-9822

DotNetNuke (DNN): Remote Code Execution

As of , CVE-2017-9822 in DotNetNuke (DNN) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 3 November 2021
US federal deadline
3 May 2022181 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.95Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
Public exploit
1 Metasploit module and 1 Exploit-DB entry (1 verified)
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

CISA's description

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

The CVE record's description, from hpe

CVE published
20 July 2017
Assigned by
hpe
CVSS
8.8 High (CVSS 3.1, from CISA-ADP)
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-20
Improper Input Validation
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. Exploit-DB published an exploit (EDB-ID 48336).
  3. CISA added it to its list of exploited vulnerabilities.
  4. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

DotNetNuke (DNN): other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2018-15811Inadequate Encryption StrengthDotNetNuke (DNN) DotNetNuke (DNN)Patch this weekMetasploit module; EPSS 0.76; verified Exploit-DB entry0.76
CVE-2018-18325Inadequate Encryption StrengthDotNetNuke (DNN) DotNetNuke (DNN)Patch this weekMetasploit module; EPSS 0.74; verified Exploit-DB entry0.74

Read further