ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.
Conclusion & alert: CVE-2017-17384 is rated Moderate Risk (60.9/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.49%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.51% | 1.49% | +0.98% |
| 2 | 2025-03-30 | 1.15% | 0.51% | -0.64% |
| 3 | 2025-03-29 | — | 1.15% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.0 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 9.0 | 2.0 | HIGH |
|
8.0 | 10.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| ispconfig | ispconfig | 3.0.2 | cpe:2.3:a:ispconfig:ispconfig:3.0.2:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.2.1 | cpe:2.3:a:ispconfig:ispconfig:3.0.2.1:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.2.2 | cpe:2.3:a:ispconfig:ispconfig:3.0.2.2:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.2.2 | cpe:2.3:a:ispconfig:ispconfig:3.0.2.2:b1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.3 | cpe:2.3:a:ispconfig:ispconfig:3.0.3:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.3 | cpe:2.3:a:ispconfig:ispconfig:3.0.3:b1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.3 | cpe:2.3:a:ispconfig:ispconfig:3.0.3:rc1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.3.1 | cpe:2.3:a:ispconfig:ispconfig:3.0.3.1:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.3.1 | cpe:2.3:a:ispconfig:ispconfig:3.0.3.1:rc1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.3.1 | cpe:2.3:a:ispconfig:ispconfig:3.0.3.1:rc2:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.3.2 | cpe:2.3:a:ispconfig:ispconfig:3.0.3.2:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.3.2 | cpe:2.3:a:ispconfig:ispconfig:3.0.3.2:rc1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.3.3 | cpe:2.3:a:ispconfig:ispconfig:3.0.3.3:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.3.3 | cpe:2.3:a:ispconfig:ispconfig:3.0.3.3:rc1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.4:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.4:b1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.4.1 | cpe:2.3:a:ispconfig:ispconfig:3.0.4.1:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.4.1 | cpe:2.3:a:ispconfig:ispconfig:3.0.4.1:rc1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.4.1 | cpe:2.3:a:ispconfig:ispconfig:3.0.4.1:rc2:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.4.2 | cpe:2.3:a:ispconfig:ispconfig:3.0.4.2:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.4.3 | cpe:2.3:a:ispconfig:ispconfig:3.0.4.3:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.4.6 | cpe:2.3:a:ispconfig:ispconfig:3.0.4.6:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.4.6 | cpe:2.3:a:ispconfig:ispconfig:3.0.4.6:rc1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5 | cpe:2.3:a:ispconfig:ispconfig:3.0.5:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5 | cpe:2.3:a:ispconfig:ispconfig:3.0.5:alpha1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5 | cpe:2.3:a:ispconfig:ispconfig:3.0.5:b1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5 | cpe:2.3:a:ispconfig:ispconfig:3.0.5:rc1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5 | cpe:2.3:a:ispconfig:ispconfig:3.0.5:rc2:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.1 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.1:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.2 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.2:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.3 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.3:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:b1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:p1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:p2:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:p3:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:p4:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:p5:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:p6:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:p7:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:p8:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:p9:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:rc1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.0.5.4 | cpe:2.3:a:ispconfig:ispconfig:3.0.5.4:rc2:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1 | cpe:2.3:a:ispconfig:ispconfig:3.1:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1.1 | cpe:2.3:a:ispconfig:ispconfig:3.1.1:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1.1 | cpe:2.3:a:ispconfig:ispconfig:3.1.1:p1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1.2 | cpe:2.3:a:ispconfig:ispconfig:3.1.2:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1.3 | cpe:2.3:a:ispconfig:ispconfig:3.1.3:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1.4 | cpe:2.3:a:ispconfig:ispconfig:3.1.4:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1.5 | cpe:2.3:a:ispconfig:ispconfig:3.1.5:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1.6 | cpe:2.3:a:ispconfig:ispconfig:3.1.6:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1.7 | cpe:2.3:a:ispconfig:ispconfig:3.1.7:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1.7 | cpe:2.3:a:ispconfig:ispconfig:3.1.7:p1:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1.8 | cpe:2.3:a:ispconfig:ispconfig:3.1.8:*:*:*:*:*:*:* |
| ispconfig | ispconfig | 3.1.8 | cpe:2.3:a:ispconfig:ispconfig:3.1.8:p1:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.ispconfig.org/blog/ispconfig-3-1-9-released-important-security-update/ | Issue Tracking Patch Vendor Advisory |