An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior. Multiple Path Traversal vulnerabilities have been identified. The flaws exist within the ActiveMQ Broker service that is installed as part of the product. By issuing specific HTTP requests, if a user visits a malicious page, an attacker can gain access to arbitrary files on the server. Smart Security Manager Versions 1.4 and prior to 1.31 are affected by these vulnerabilities. These vulnerabilities can allow for remote code execution.
Conclusion & alert: CVE-2017-5168 is rated Moderate Risk (59.9/100): CVSS High severity, with medium exploitation likelihood (EPSS 4.32%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-30 | 5.21% | 4.32% | -0.88% |
| 2 | 2025-03-29 | 4.32% | 5.21% | +0.88% |
| 3 | 2025-03-17 | — | 4.32% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
1.6 | 5.9 | [email protected] |
| 5.1 | 2.0 | MEDIUM |
|
4.9 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| hanwha-security | smart_security_manager | <= 1.5 | cpe:2.3:a:hanwha-security:smart_security_manager:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/96147 | Third Party Advisory VDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-17-040-01 | Patch Third Party Advisory US Government Resource |