CVE-2017-16651General(debian / debian_linux)

LOWCVSS 7.8 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-552

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • webmail

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
debian_linuxwebmail

12 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-12: 103-12
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Alone@alodotne
    General

    @the_real_egg_f @ProtonMail I'm confused? A webmail client is better than the actual email service it self?! CVE-2025-68461 CVE-2025-49113 CVE-2025-68460 CVE-2024-42009 CVE-2024-37385 CVE-2023-5631 CVE-2021-44026 CVE-2020-12641 CVE-2017-16651

    Post summary

    The tweet simply lists multiple CVE identifiers without providing any additional context, details, or actionable information.

    10000174
    54 followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux7.0--
OSdebiandebian_linux9.0--
Approundcubewebmail---
Approundcubewebmail1.2.0--
Approundcubewebmail1.2.1--
Approundcubewebmail1.2.2--
Approundcubewebmail1.2.3--
Approundcubewebmail1.2.4--
Approundcubewebmail1.2.5--
Approundcubewebmail1.2.6--
Approundcubewebmail1.3.0--
Approundcubewebmail1.3.1--
Approundcubewebmail1.3.2--

Explore more