S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-17562 Scanner

CVE-2017-17562 scanner - Remote Code Execution (RCE) vulnerability in GoAhead Web Server

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2017-17562
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 5, 2026View on NVD →
Detail

The GoAhead Web Server is a popular embedded web server used for a wide range of applications, including home automation, security systems, and industrial control systems. It is known for its lightweight and cross-platform capabilities, making it a popular choice for developers looking to build web applications for these specific niches. GoAhead can be customized and compiled for Linux, BSD, and other operating systems, giving it greater flexibility and versatility than other web servers on the market.

CVE-2017-17562 is a critical vulnerability that was detected in GoAhead version 3.6.5 and below. This vulnerability allows remote code execution if Common Gateway Interface (CGI) is enabled, and a CGI program is dynamically linked. CGI scripts are a popular way of generating dynamic web content, and when combined with the glibc dynamic linker, this vulnerability can be easily exploited by attackers. Specifically, it occurs when untrusted HTTP request parameters are used to initialize the environment of forked CGI scripts in the cgiHandler function in cgi.c. This means that an attacker can post their payload in the body of the request, and reference it using /proc/self/fd/0.

Exploitation of CVE-2017-17562 can lead to a range of serious consequences, including unauthorized access to sensitive data, system compromise, and the ability to execute arbitrary code on the affected server. This vulnerability can also be used as a stepping stone for actors looking to move laterally across an organization's network through privilege escalation and lateral movement. The consequences of the exploitation of this vulnerability can be far-reaching and highly destructive.

In conclusion, maintaining the security of your digital assets is critical to the success and continuity of any business or organization. Thanks to the pro features of the s4e.io platform, staying informed about vulnerabilities in your digital assets has never been easier. By leveraging the power of this platform, you can easily and quickly identify potential vulnerabilities in your infrastructure, assess potential risks, and take appropriate steps to mitigate them before they can be exploited by attackers. Protecting against vulnerabilities like CVE-2017-17562 is just one aspect of a comprehensive security program, and using the right tools and strategies is critical to success.

 

REFERENCES

Solution Advice

There are several measures that can be taken to protect against CVE-2017-17562. These include:

  • Applying security patches for GoAhead Web Server as soon as they become available
  • Disabling CGI if not needed or required
  • Using web application firewalls and intrusion detection systems to block attacks
  • Implementing network segmentation to limit the spread of potential attacks
  • Regularly performing vulnerability assessments and penetration testing to identify and mitigate potential risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-17562 scanner - Remote Code Execution (RCE) vulnerability in GoAhead Web Server | S4E