{"api_version":"1","generated_at":"2026-07-23T14:21:30+00:00","cve":"CVE-2017-10815","urls":{"html":"https://cve.report/CVE-2017-10815","api":"https://cve.report/api/cve/CVE-2017-10815.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-10815","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-10815"},"summary":{"title":"CVE-2017-10815","description":"MaLion for Windows 5.2.1 and earlier (only when \"Remote Control\" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when \"Remote Control\" is installed) allow remote attackers to bypass authentication to execute arbitrary commands or operations on Terminal Agent.","state":"PUBLISHED","assigner":"jpcert","published_at":"2017-08-04 16:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-287","Authentication bypass"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"8.1","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.intercom.co.jp/information/2017/0801.html","name":"http://www.intercom.co.jp/information/2017/0801.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MaLion シリーズの脆弱性につきまして","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://jvn.jp/en/vu/JVNVU91587298/index.html","name":"https://jvn.jp/en/vu/JVNVU91587298/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"JVNVU#91587298: Multiple vulnerabilities in MaLion","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-10815","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-10815","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Intercom, Inc.","product":"MaLion for Windows","version":"affected 5.2.1 and earlier (only when \"Remote Control\" is installed)","platforms":[]},{"source":"CNA","vendor":"Intercom, Inc.","product":"MaLion for Mac","version":"affected 4.0.1 to  5.2.1 (only when \"Remote Control\" is installed)","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"10815","vulnerable":"1","versionEndIncluding":"5.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"intercom","cpe5":"malion","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"mac_os_x","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"10815","vulnerable":"1","versionEndIncluding":"5.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"intercom","cpe5":"malion","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T17:50:12.095Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.intercom.co.jp/information/2017/0801.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://jvn.jp/en/vu/JVNVU91587298/index.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"MaLion for Windows","vendor":"Intercom, Inc.","versions":[{"status":"affected","version":"5.2.1 and earlier (only when \"Remote Control\" is installed)"}]},{"product":"MaLion for Mac","vendor":"Intercom, Inc.","versions":[{"status":"affected","version":"4.0.1 to  5.2.1 (only when \"Remote Control\" is installed)"}]}],"datePublic":"2017-08-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"MaLion for Windows 5.2.1 and earlier (only when \"Remote Control\" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when \"Remote Control\" is installed) allow remote attackers to bypass authentication to execute arbitrary commands or operations on Terminal Agent."}],"problemTypes":[{"descriptions":[{"description":"Authentication bypass","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-11T01:57:01.000Z","orgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","shortName":"jpcert"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.intercom.co.jp/information/2017/0801.html"},{"tags":["x_refsource_MISC"],"url":"https://jvn.jp/en/vu/JVNVU91587298/index.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"vultures@jpcert.or.jp","ID":"CVE-2017-10815","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"MaLion for Windows","version":{"version_data":[{"version_value":"5.2.1 and earlier (only when \"Remote Control\" is installed)"}]}},{"product_name":"MaLion for Mac","version":{"version_data":[{"version_value":"4.0.1 to  5.2.1 (only when \"Remote Control\" is installed)"}]}}]},"vendor_name":"Intercom, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"MaLion for Windows 5.2.1 and earlier (only when \"Remote Control\" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when \"Remote Control\" is installed) allow remote attackers to bypass authentication to execute arbitrary commands or operations on Terminal Agent."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Authentication bypass"}]}]},"references":{"reference_data":[{"name":"http://www.intercom.co.jp/information/2017/0801.html","refsource":"MISC","url":"http://www.intercom.co.jp/information/2017/0801.html"},{"name":"https://jvn.jp/en/vu/JVNVU91587298/index.html","refsource":"MISC","url":"https://jvn.jp/en/vu/JVNVU91587298/index.html"}]}}}},"cveMetadata":{"assignerOrgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","assignerShortName":"jpcert","cveId":"CVE-2017-10815","datePublished":"2017-08-04T16:00:00.000Z","dateReserved":"2017-07-04T00:00:00.000Z","dateUpdated":"2024-08-05T17:50:12.095Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-08-04 16:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-287","Authentication bypass"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:intercom:malion:*:*:*:*:*:mac_os_x:*:*","versionEndIncluding":"5.2.1","matchCriteriaId":"4B1C3A9B-1A0C-4E71-9532-4F6026CC935B"},{"vulnerable":true,"criteria":"cpe:2.3:a:intercom:malion:*:*:*:*:*:windows:*:*","versionEndIncluding":"5.2.1","matchCriteriaId":"BAB50670-B628-4109-8CB8-AC1B9A6071F1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"10815","Ordinal":"1","Title":"CVE-2017-10815","CVE":"CVE-2017-10815","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"10815","Ordinal":"1","NoteData":"MaLion for Windows 5.2.1 and earlier (only when \"Remote Control\" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when \"Remote Control\" is installed) allow remote attackers to bypass authentication to execute arbitrary commands or operations on Terminal Agent.","Type":"Description","Title":"CVE-2017-10815"},{"CveYear":"2017","CveId":"10815","Ordinal":"2","NoteData":"2017-08-04","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"10815","Ordinal":"3","NoteData":"2017-08-10","Type":"Other","Title":"Modified"}]}}}