CVE-2017-9822: DotNetNuke (DNN) Remote Code Execution Vulnerability
Published Jul 20, 2017
·Updated
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
Other sources
DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.
— CISA
Affected Software
3 affected components
DotNetNuke (DNN) DotNetNuke (DNN)
dnnsoftware Dotnetnuke<=9.1.0
dnnsoftware Dotnetnuke<9.1.1
Event History
Jul 20, 2017
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Data Sourced
via NVD·12:29 PM
DescriptionSeverityWeaknessAffected Software
Nov 3, 2021
Known Exploited
via CISA·12:00 AM
Known Ransomware
via CISA·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-9822?
CVE-2017-9822 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2017-9822?
To mitigate CVE-2017-9822, upgrade to DotNetNuke version 9.1.1 or later.
3
What kind of attack does CVE-2017-9822 enable?
CVE-2017-9822 enables attackers to execute remote code via cookie deserialization.
4
Which versions of DotNetNuke are affected by CVE-2017-9822?
CVE-2017-9822 affects DotNetNuke versions prior to 9.1.1.
5
Is CVE-2017-9822 still a threat today?
CVE-2017-9822 may still pose a threat if vulnerable versions of DotNetNuke remain in use.