{"api_version":"1","generated_at":"2026-07-23T07:18:19+00:00","cve":"CVE-2017-20011","urls":{"html":"https://cve.report/CVE-2017-20011","api":"https://cve.report/api/cve/CVE-2017-20011.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-20011","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-20011"},"summary":{"title":"CVE-2017-20011","description":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WEKA INTEREST Security Scanner 1.8. It has been rated as problematic. This issue affects some unknown processing of the component HTTP Handler. The manipulation with an unknown input leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2022-03-28 21:15:00","updated_at":"2023-11-07 02:43:00"},"problem_types":["CWE-404"],"metrics":[],"references":[{"url":"http://www.computec.ch/news.php?item.117","name":"http://www.computec.ch/news.php?item.117","refsource":"MISC","tags":[],"title":"computec.ch • 1997 - 2018","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://vuldb.com/?id.101969","name":"https://vuldb.com/?id.101969","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-20011","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-20011","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"20011","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"weka","cpe5":"interest_security_scanner","cpe6":"1.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2017-20011","TITLE":"WEKA INTEREST Security Scanner HTTP denial of service","REQUESTER":"cna@vuldb.com","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"generator":"vuldb.com","affects":{"vendor":{"vendor_data":[{"vendor_name":"WEKA","product":{"product_data":[{"product_name":"INTEREST Security Scanner","version":{"version_data":[{"version_value":"1.8"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-404 Denial of Service"}]}]},"description":{"description_data":[{"lang":"eng","value":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WEKA INTEREST Security Scanner 1.8. It has been rated as problematic. This issue affects some unknown processing of the component HTTP Handler. The manipulation with an unknown input leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer."}]},"credit":"Marc Ruef","impact":{"cvss":{"version":"3.1","baseScore":"2.8","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.101969","refsource":"MISC","name":"https://vuldb.com/?id.101969"},{"url":"http://www.computec.ch/news.php?item.117","refsource":"MISC","name":"http://www.computec.ch/news.php?item.117"}]}},"nvd":{"publishedDate":"2022-03-28 21:15:00","lastModifiedDate":"2023-11-07 02:43:00","problem_types":["CWE-404"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:weka:interest_security_scanner:1.8:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"20011","Ordinal":"227329","Title":"CVE-2017-20011","CVE":"CVE-2017-20011","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"20011","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}