Vulnerability Details CVE-2017-1000203
ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution
Exploit prediction scoring system (EPSS) score
EPSS Score 0.022
EPSS Ranking 83.9%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2017-1000203
-
cpe:2.3:a:cern:root:-12-00a
-
cpe:2.3:a:cern:root:2-24-05
-
-
cpe:2.3:a:cern:root:2-25-00
-
cpe:2.3:a:cern:root:2-25-01
-
cpe:2.3:a:cern:root:2-25-02
-
cpe:2.3:a:cern:root:2-25-03
-
-
cpe:2.3:a:cern:root:2-26-00
-
cpe:2.3:a:cern:root:2-26-01
-
cpe:2.3:a:cern:root:3-00-01
-
cpe:2.3:a:cern:root:3-00-02
-
cpe:2.3:a:cern:root:3-00-04
-
cpe:2.3:a:cern:root:3-00-05
-
cpe:2.3:a:cern:root:3-00-06
-
cpe:2.3:a:cern:root:3-01-01
-
cpe:2.3:a:cern:root:3-01-02
-
cpe:2.3:a:cern:root:3-01-03
-
cpe:2.3:a:cern:root:3-01-05
-
cpe:2.3:a:cern:root:3-01-06
-
cpe:2.3:a:cern:root:3-02-00
-
cpe:2.3:a:cern:root:3-02-01
-
cpe:2.3:a:cern:root:3-02-02
-
cpe:2.3:a:cern:root:3-02-03
-
cpe:2.3:a:cern:root:3-02-04
-
cpe:2.3:a:cern:root:3-02-05
-
cpe:2.3:a:cern:root:3-02-06
-
cpe:2.3:a:cern:root:3-02-07
-
cpe:2.3:a:cern:root:3-03-01
-
cpe:2.3:a:cern:root:3-03-02
-
cpe:2.3:a:cern:root:3-03-03
-
cpe:2.3:a:cern:root:3-03-04
-
cpe:2.3:a:cern:root:3-03-05
-
cpe:2.3:a:cern:root:3-03-06
-
cpe:2.3:a:cern:root:3-03-07
-
cpe:2.3:a:cern:root:3-03-08
-
cpe:2.3:a:cern:root:3-03-09
-
cpe:2.3:a:cern:root:3-03-09a
-
cpe:2.3:a:cern:root:3-03-09b
-
cpe:2.3:a:cern:root:3-04-01
-
cpe:2.3:a:cern:root:3-04-02
-
cpe:2.3:a:cern:root:3-05-00
-
cpe:2.3:a:cern:root:3-05-01
-
cpe:2.3:a:cern:root:3-05-02
-
cpe:2.3:a:cern:root:3-05-03
-
cpe:2.3:a:cern:root:3-05-04
-
cpe:2.3:a:cern:root:3-05-05
-
cpe:2.3:a:cern:root:3-05-06
-
cpe:2.3:a:cern:root:3-05-07
-
cpe:2.3:a:cern:root:3-05-07a
-
cpe:2.3:a:cern:root:3-10-01
-
cpe:2.3:a:cern:root:3-10-01a
-
cpe:2.3:a:cern:root:3-10-02
-
cpe:2.3:a:cern:root:3-10-03
-
cpe:2.3:a:cern:root:4-00-01
-
cpe:2.3:a:cern:root:4-00-02
-
cpe:2.3:a:cern:root:4-00-03
-
cpe:2.3:a:cern:root:4-00-04
-
cpe:2.3:a:cern:root:4-00-06
-
cpe:2.3:a:cern:root:4-00-06a
-
cpe:2.3:a:cern:root:4-00-08
-
cpe:2.3:a:cern:root:4-00-08a
-
cpe:2.3:a:cern:root:4-00-08b
-
cpe:2.3:a:cern:root:4-00-08d
-
cpe:2.3:a:cern:root:4-00-08e
-
cpe:2.3:a:cern:root:4-00-08f
-
cpe:2.3:a:cern:root:4-01-02
-
cpe:2.3:a:cern:root:4-01-04
-
cpe:2.3:a:cern:root:4-01-04a
-
cpe:2.3:a:cern:root:4-02-00
-
cpe:2.3:a:cern:root:4-03-02
-
cpe:2.3:a:cern:root:4-03-04
-
cpe:2.3:a:cern:root:4-03-04a
-
cpe:2.3:a:cern:root:4-04-02
-
cpe:2.3:a:cern:root:4-04-02a
-
cpe:2.3:a:cern:root:4-04-02b
-
cpe:2.3:a:cern:root:4-04-02c
-
cpe:2.3:a:cern:root:4-04-02d
-
cpe:2.3:a:cern:root:4-04-02e
-
cpe:2.3:a:cern:root:4-04-02f
-
cpe:2.3:a:cern:root:4-04-02g
-
cpe:2.3:a:cern:root:5-02-00
-
cpe:2.3:a:cern:root:5-03-01
-
cpe:2.3:a:cern:root:5-04-00
-
cpe:2.3:a:cern:root:5-05-01
-
cpe:2.3:a:cern:root:5-06-00
-
cpe:2.3:a:cern:root:5-08-00
-
cpe:2.3:a:cern:root:5-08-00a
-
cpe:2.3:a:cern:root:5-08-00b
-
cpe:2.3:a:cern:root:5-09-01
-
cpe:2.3:a:cern:root:5-10-00
-
cpe:2.3:a:cern:root:5-10-00a
-
cpe:2.3:a:cern:root:5-10-00b
-
cpe:2.3:a:cern:root:5-10-00c
-
cpe:2.3:a:cern:root:5-10-00d
-
cpe:2.3:a:cern:root:5-10-00e
-
cpe:2.3:a:cern:root:5-10-00f
-
cpe:2.3:a:cern:root:5-11-01
-
cpe:2.3:a:cern:root:5-11-02
-
cpe:2.3:a:cern:root:5-11-04
-
cpe:2.3:a:cern:root:5-11-06
-
cpe:2.3:a:cern:root:5-11-06a
-
cpe:2.3:a:cern:root:5-12-00
-
cpe:2.3:a:cern:root:5-12-00b
-
cpe:2.3:a:cern:root:5-12-00c
-
cpe:2.3:a:cern:root:5-12-00d
-
cpe:2.3:a:cern:root:5-12-00e
-
cpe:2.3:a:cern:root:5-12-00f
-
cpe:2.3:a:cern:root:5-12-00g
-
cpe:2.3:a:cern:root:5-12-00h
-
cpe:2.3:a:cern:root:5-13-02
-
cpe:2.3:a:cern:root:5-13-04
-
cpe:2.3:a:cern:root:5-13-04a
-
cpe:2.3:a:cern:root:5-13-04b
-
cpe:2.3:a:cern:root:5-13-04c
-
cpe:2.3:a:cern:root:5-13-04d
-
cpe:2.3:a:cern:root:5-13-04e
-
cpe:2.3:a:cern:root:5-13-06
-
cpe:2.3:a:cern:root:5-14-00
-
cpe:2.3:a:cern:root:5-14-00a
-
cpe:2.3:a:cern:root:5-14-00b
-
cpe:2.3:a:cern:root:5-14-00c
-
cpe:2.3:a:cern:root:5-14-00d
-
cpe:2.3:a:cern:root:5-14-00e
-
cpe:2.3:a:cern:root:5-14-00f
-
cpe:2.3:a:cern:root:5-14-00g
-
cpe:2.3:a:cern:root:5-14-00h
-
cpe:2.3:a:cern:root:5-14-00i
-
cpe:2.3:a:cern:root:5-15-02
-
cpe:2.3:a:cern:root:5-15-04
-
cpe:2.3:a:cern:root:5-15-06
-
cpe:2.3:a:cern:root:5-15-08
-
cpe:2.3:a:cern:root:5-16-00
-
cpe:2.3:a:cern:root:5-16-14
-
cpe:2.3:a:cern:root:5-16-15
-
cpe:2.3:a:cern:root:5-16-16
-
cpe:2.3:a:cern:root:5-16-17
-
cpe:2.3:a:cern:root:5-16-18
-
cpe:2.3:a:cern:root:5-16-19
-
cpe:2.3:a:cern:root:5-16-20
-
cpe:2.3:a:cern:root:5-16-21
-
cpe:2.3:a:cern:root:5-16-22
-
cpe:2.3:a:cern:root:5-16-23
-
cpe:2.3:a:cern:root:5-16-24
-
cpe:2.3:a:cern:root:5-16-25
-
cpe:2.3:a:cern:root:5-17-02
-
cpe:2.3:a:cern:root:5-17-03a
-
cpe:2.3:a:cern:root:5-17-04
-
cpe:2.3:a:cern:root:5-17-06
-
cpe:2.3:a:cern:root:5-17-08
-
cpe:2.3:a:cern:root:5-18-00
-
cpe:2.3:a:cern:root:5-18-00a
-
cpe:2.3:a:cern:root:5-18-00b
-
cpe:2.3:a:cern:root:5-18-00c
-
cpe:2.3:a:cern:root:5-18-00d
-
cpe:2.3:a:cern:root:5-18-00e
-
cpe:2.3:a:cern:root:5-18-00f
-
cpe:2.3:a:cern:root:5-19-02
-
cpe:2.3:a:cern:root:5-19-02a
-
cpe:2.3:a:cern:root:5-19-04
-
cpe:2.3:a:cern:root:5-20-00
-
cpe:2.3:a:cern:root:5-21-01
-
cpe:2.3:a:cern:root:5-21-02
-
cpe:2.3:a:cern:root:5-21-04
-
cpe:2.3:a:cern:root:5-21-06
-
cpe:2.3:a:cern:root:5-22-00
-
cpe:2.3:a:cern:root:5-22-00a
-
cpe:2.3:a:cern:root:5-22-00b
-
cpe:2.3:a:cern:root:5-22-00c
-
cpe:2.3:a:cern:root:5-22-00d
-
cpe:2.3:a:cern:root:5-22-00e
-
cpe:2.3:a:cern:root:5-22-00f
-
cpe:2.3:a:cern:root:5-22-00g
-
cpe:2.3:a:cern:root:5-22-00h
-
cpe:2.3:a:cern:root:5-22-00i
-
cpe:2.3:a:cern:root:5-22-00j
-
cpe:2.3:a:cern:root:5-23-02
-
cpe:2.3:a:cern:root:5-23-04
-
cpe:2.3:a:cern:root:5-24-00
-
cpe:2.3:a:cern:root:5-24-00a
-
cpe:2.3:a:cern:root:5-24-00b
-
cpe:2.3:a:cern:root:5-25-01
-
cpe:2.3:a:cern:root:5-25-02
-
cpe:2.3:a:cern:root:5-25-04
-
cpe:2.3:a:cern:root:5-26-00
-
cpe:2.3:a:cern:root:5-26-00a
-
cpe:2.3:a:cern:root:5-26-00b
-
cpe:2.3:a:cern:root:5-26-00c
-
cpe:2.3:a:cern:root:5-26-00d
-
cpe:2.3:a:cern:root:5-26-00e
-
cpe:2.3:a:cern:root:5-26-00f
-
cpe:2.3:a:cern:root:5-26-00g
-
cpe:2.3:a:cern:root:5-27-02
-
cpe:2.3:a:cern:root:5-27-04
-
cpe:2.3:a:cern:root:5-27-06
-
cpe:2.3:a:cern:root:5-27-06a
-
cpe:2.3:a:cern:root:5-27-06b
-
cpe:2.3:a:cern:root:5-27-06c
-
cpe:2.3:a:cern:root:5-27-06d
-
cpe:2.3:a:cern:root:5-28-00
-
cpe:2.3:a:cern:root:5-28-00a
-
cpe:2.3:a:cern:root:5-28-00b
-
cpe:2.3:a:cern:root:5-28-00c
-
cpe:2.3:a:cern:root:5-28-00d
-
cpe:2.3:a:cern:root:5-28-00e
-
cpe:2.3:a:cern:root:5-28-00f
-
cpe:2.3:a:cern:root:5-28-00g
-
cpe:2.3:a:cern:root:5-28-00h
-
cpe:2.3:a:cern:root:5-29-02
-
cpe:2.3:a:cern:root:5-30-00
-
cpe:2.3:a:cern:root:5-30-01
-
cpe:2.3:a:cern:root:5-30-02
-
cpe:2.3:a:cern:root:5-30-03
-
cpe:2.3:a:cern:root:5-30-04
-
cpe:2.3:a:cern:root:5-30-05
-
cpe:2.3:a:cern:root:5-30-06
-
cpe:2.3:a:cern:root:5-32-00
-
cpe:2.3:a:cern:root:5-32-01
-
cpe:2.3:a:cern:root:5-32-02
-
cpe:2.3:a:cern:root:5-32-03
-
cpe:2.3:a:cern:root:5-32-04
-
cpe:2.3:a:cern:root:5-33-02
-
cpe:2.3:a:cern:root:5-33-02a
-
cpe:2.3:a:cern:root:5-33-02b
-
cpe:2.3:a:cern:root:5-34-00
-
cpe:2.3:a:cern:root:5-34-01
-
cpe:2.3:a:cern:root:5-34-02
-
cpe:2.3:a:cern:root:5-34-03
-
cpe:2.3:a:cern:root:5-34-04
-
cpe:2.3:a:cern:root:5-34-05
-
cpe:2.3:a:cern:root:5-34-06
-
cpe:2.3:a:cern:root:5-34-07
-
cpe:2.3:a:cern:root:5-34-08
-
cpe:2.3:a:cern:root:5-34-09
-
cpe:2.3:a:cern:root:5-34-10
-
cpe:2.3:a:cern:root:5-34-11
-
cpe:2.3:a:cern:root:5-34-12
-
cpe:2.3:a:cern:root:5-34-13
-
cpe:2.3:a:cern:root:5-34-14
-
cpe:2.3:a:cern:root:5-34-15
-
cpe:2.3:a:cern:root:5-34-16
-
cpe:2.3:a:cern:root:5-34-17
-
cpe:2.3:a:cern:root:5-34-18
-
cpe:2.3:a:cern:root:5-34-19
-
cpe:2.3:a:cern:root:5-34-20
-
cpe:2.3:a:cern:root:5-34-21
-
cpe:2.3:a:cern:root:5-34-22
-
cpe:2.3:a:cern:root:5-34-23
-
cpe:2.3:a:cern:root:5-34-24
-
cpe:2.3:a:cern:root:5-34-25
-
cpe:2.3:a:cern:root:5-34-26
-
cpe:2.3:a:cern:root:5-34-28
-
cpe:2.3:a:cern:root:5-34-30
-
cpe:2.3:a:cern:root:5-34-32
-
cpe:2.3:a:cern:root:5-34-34
-
cpe:2.3:a:cern:root:5-34-36
-
cpe:2.3:a:cern:root:5-99-02
-
cpe:2.3:a:cern:root:5-99-03
-
cpe:2.3:a:cern:root:5-99-04
-
cpe:2.3:a:cern:root:5-99-05
-
cpe:2.3:a:cern:root:5-99-06
-
cpe:2.3:a:cern:root:6-00-00
-
cpe:2.3:a:cern:root:6-00-01
-
cpe:2.3:a:cern:root:6-00-02
-
cpe:2.3:a:cern:root:6-01-03
-
cpe:2.3:a:cern:root:6-02-00
-
cpe:2.3:a:cern:root:6-02-01
-
cpe:2.3:a:cern:root:6-02-02
-
cpe:2.3:a:cern:root:6-02-03
-
cpe:2.3:a:cern:root:6-02-04
-
cpe:2.3:a:cern:root:6-02-05
-
cpe:2.3:a:cern:root:6-02-08
-
cpe:2.3:a:cern:root:6-02-10
-
cpe:2.3:a:cern:root:6-02-12
-
cpe:2.3:a:cern:root:6-03-01
-
cpe:2.3:a:cern:root:6-03-02
-
cpe:2.3:a:cern:root:6-03-04
-
cpe:2.3:a:cern:root:6-04-00
-
cpe:2.3:a:cern:root:6-04-02
-
cpe:2.3:a:cern:root:6-04-04
-
cpe:2.3:a:cern:root:6-04-06
-
cpe:2.3:a:cern:root:6-04-08
-
cpe:2.3:a:cern:root:6-04-10
-
cpe:2.3:a:cern:root:6-04-12
-
cpe:2.3:a:cern:root:6-04-14
-
cpe:2.3:a:cern:root:6-04-16
-
cpe:2.3:a:cern:root:6-04-18
-
cpe:2.3:a:cern:root:6-05-01
-
cpe:2.3:a:cern:root:6-05-02
-
cpe:2.3:a:cern:root:6-06-00
-
cpe:2.3:a:cern:root:6-06-02
-
cpe:2.3:a:cern:root:6-06-04
-
cpe:2.3:a:cern:root:6-06-06
-
cpe:2.3:a:cern:root:6-06-08
-
cpe:2.3:a:cern:root:6-07-01
-
cpe:2.3:a:cern:root:6-07-02
-
cpe:2.3:a:cern:root:6-07-04
-
cpe:2.3:a:cern:root:6-07-06
-
cpe:2.3:a:cern:root:6-07-07
-
cpe:2.3:a:cern:root:6-08-00
-
cpe:2.3:a:cern:root:6-08-02
-
cpe:2.3:a:cern:root:6-08-04
-
cpe:2.3:a:cern:root:6-08-06
-
cpe:2.3:a:cern:root:6-09-01
-
cpe:2.3:a:cern:root:6-09-02
-
cpe:2.3:a:cern:root:6-09-04
-
cpe:2.3:a:cern:root:6-10-00
-
cpe:2.3:a:cern:root:6-10-02
-
cpe:2.3:a:cern:root:6-10-04
-
cpe:2.3:a:cern:root:6-10-06
-
cpe:2.3:a:cern:root:6-10-08
-
cpe:2.3:a:cern:root:6-11-02