Junglewise Threat Intelligence

CVE-2017-9822: DNN (aka DotNetNuke) has Remote Code Execution via a cookie

CVE-2017-9822 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2018-10-16

Technologies: Dotnetnuke (Dnn), DotNetNuke.Core (NuGet). Vendors: Dotnetnuke (Dnn), NuGet.

Executive brief

DotNetNuke (DNN) versions prior to 9.1.1 are vulnerable to remote code execution via insecure deserialization of data within a cookie. An attacker can exploit this to execute arbitrary code on the server.

Affected products

  • DNN Software DotNetNuke (DNN) before 9.1.1

Timeline

  • 2017-07-21: disclosed: Initial vendor advisory/description update
  • 2017-07-25: other: Initial NIST analysis completed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-03: other: Due date for remediation per CISA BOD 22-01

Related threats