VYPR

Serviio PRO

by Serviio

CVEs (3)

  • CVE-2017-20218HigMar 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Serviio PRO 1.8 contains an unquoted search path vulnerability in the Windows service that allows local users to execute arbitrary code with elevated privileges by placing malicious executables in the system root path. Additionally, improper directory permissions with full…

  • CVE-2017-20220HigMar 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the mediabrowser login password. Attackers can send specially crafted requests to the REST API endpoints to modify credentials without…

  • CVE-2017-20217HigMar 16, 2026
    risk 0.49cvss 7.5epss 0.01

    Serviio PRO 1.8 contains an information disclosure vulnerability due to improper access control enforcement in the Configuration REST API that allows unauthenticated attackers to access sensitive information. Remote attackers can send specially crafted requests to the REST API…