First published: Mon Aug 05 2019(Updated: )
cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=11.54.0.0<11.54.0.36 | |
Cpanel Cpanel | >=55.9999.61<56.0.43 | |
Cpanel Cpanel | >=57.9999.48<58.0.43 | |
Cpanel Cpanel | >=59.9999.58<60.0.35 | |
Cpanel Cpanel | >=61.9999.55<62.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18470 has a medium severity rating due to the presence of a fixed password for the Munin MySQL test account.
To fix CVE-2017-18470, upgrade to cPanel version 62.0.4 or later where the fixed password issue is addressed.
CVE-2017-18470 affects cPanel versions prior to 62.0.4, specifically versions 11.54.0.36 and earlier, 56.0.43 and earlier, 58.0.43 and earlier, and 60.0.35 and earlier.
Yes, CVE-2017-18470 can be exploited remotely as it involves a fixed password for a MySQL test account.
The impact of CVE-2017-18470 is that it may allow unauthorized access to the Munin MySQL test account, compromising sensitive information.