{"api_version":"1","generated_at":"2026-07-24T18:40:00+00:00","cve":"CVE-2017-20014","urls":{"html":"https://cve.report/CVE-2017-20014","api":"https://cve.report/api/cve/CVE-2017-20014.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-20014","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-20014"},"summary":{"title":"CVE-2017-20014","description":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in WEKA INTEREST Security Scanner up to 1.8. Affected by this issue is some unknown functionality of the component Webspider. The manipulation with an unknown input leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2022-03-28 21:15:00","updated_at":"2023-11-07 02:43:00"},"problem_types":["CWE-404"],"metrics":[],"references":[{"url":"http://www.computec.ch/news.php?item.117","name":"http://www.computec.ch/news.php?item.117","refsource":"MISC","tags":[],"title":"computec.ch • 1997 - 2018","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://vuldb.com/?id.101969","name":"https://vuldb.com/?id.101969","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://vuldb.com/?id.101972","name":"https://vuldb.com/?id.101972","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-20014","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-20014","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"20014","vulnerable":"1","versionEndIncluding":"1.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"weka","cpe5":"interest_security_scanner","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2017-20014","TITLE":"WEKA INTEREST Security Scanner Webspider denial of service","REQUESTER":"cna@vuldb.com","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"generator":"vuldb.com","affects":{"vendor":{"vendor_data":[{"vendor_name":"WEKA","product":{"product_data":[{"product_name":"INTEREST Security Scanner","version":{"version_data":[{"version_value":"1.0"},{"version_value":"1.1"},{"version_value":"1.2"},{"version_value":"1.3"},{"version_value":"1.4"},{"version_value":"1.5"},{"version_value":"1.6"},{"version_value":"1.7"},{"version_value":"1.8"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-404 Denial of Service"}]}]},"description":{"description_data":[{"lang":"eng","value":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in WEKA INTEREST Security Scanner up to 1.8. Affected by this issue is some unknown functionality of the component Webspider. The manipulation with an unknown input leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer."}]},"credit":"Marc Ruef","impact":{"cvss":{"version":"3.1","baseScore":"2.8","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.101969","refsource":"MISC","name":"https://vuldb.com/?id.101969"},{"url":"http://www.computec.ch/news.php?item.117","refsource":"MISC","name":"http://www.computec.ch/news.php?item.117"},{"url":"https://vuldb.com/?id.101972","refsource":"MISC","name":"https://vuldb.com/?id.101972"}]}},"nvd":{"publishedDate":"2022-03-28 21:15:00","lastModifiedDate":"2023-11-07 02:43:00","problem_types":["CWE-404"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:weka:interest_security_scanner:*:*:*:*:*:*:*:*","versionEndIncluding":"1.8","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"20014","Ordinal":"227333","Title":"CVE-2017-20014","CVE":"CVE-2017-20014","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"20014","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}