CVE-2017-18470: High severity cpanel vulnerability
Published Aug 5, 2019
·Updated
cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).
Affected Software
5 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.36
Cpanel Cpanel>=55.9999.61<56.0.43
Cpanel Cpanel>=57.9999.48<58.0.43
Cpanel Cpanel>=59.9999.58<60.0.35
Cpanel Cpanel>=61.9999.55<62.0.4
Event History
Aug 5, 2019
CVE Published
via MITRE·12:41 PM
Data Sourced
via MITRE·12:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18470?
CVE-2017-18470 has a medium severity rating due to the presence of a fixed password for the Munin MySQL test account.
2
How do I fix CVE-2017-18470?
To fix CVE-2017-18470, upgrade to cPanel version 62.0.4 or later where the fixed password issue is addressed.
3
What software is affected by CVE-2017-18470?
CVE-2017-18470 affects cPanel versions prior to 62.0.4, specifically versions 11.54.0.36 and earlier, 56.0.43 and earlier, 58.0.43 and earlier, and 60.0.35 and earlier.
4
Is CVE-2017-18470 exploitable remotely?
Yes, CVE-2017-18470 can be exploited remotely as it involves a fixed password for a MySQL test account.
5
What impact does CVE-2017-18470 have on security?
The impact of CVE-2017-18470 is that it may allow unauthorized access to the Munin MySQL test account, compromising sensitive information.