CVE Tools

CVE-2017-9812

Published: Jul 17, 2017Updated: May 13, 2026 Sources: CVE List NVD BDUCWE-200

Description

The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges.

In plain language

AI Worth attention

This bug in Kaspersky Anti-Virus for Linux File Server lets an attacker use the web interface to read any file on the server without a login, so you should treat it as an active security risk if you expose the web interface to the internet.

Executive summary

Unauthenticated network abuse of the Kaspersky Anti-Virus for Linux File Server web interface allows attackers to manipulate the reportId parameter in the getReportStatus action method to read arbitrary files with limited server privileges.

If affected, business impact
Confidential files exposedCredentials or sensitive data theftService disruption riskRegulatory exposure

What to do now

  1. Check whether your Kaspersky Anti-Virus for Linux File Server version is before “Maintenance Pack 2 Critical Fix 4 (8.0.4.312)”.
  2. Check whether the product’s web interface is reachable from outside your network (for example, accessible from the internet or from untrusted networks).
  3. If it is reachable or you’re unsure, immediately restrict access to the web interface to only trusted IPs or internal networks.
  4. Upgrade/apply the fix to Maintenance Pack 2 Critical Fix 4 (8.0.4.312) or later, following your vendor’s upgrade guidance.
  5. After upgrading, monitor for unusual web requests to the getReportStatus area and review logs for abnormal attempts to access report/status endpoints.
Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:NA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:NIntegrity
None
A:NAvailability
None

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

4 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Collection
View detailed technique mapping

References

and 7 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2017-9812 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store