PT-2026-25738 · Undefined · Undefined

Published

2026-03-15

·

Updated

2026-03-16

·

CVE-2017-20220

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Serviio PRO version 1.8
Description Serviio PRO version 1.8 has an improper access control issue in the Configuration REST API. This allows unauthenticated attackers to modify the mediabrowser login password by sending crafted requests to the REST API endpoints without needing to authenticate. The vulnerable API allows modification of credentials without authorization.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2017-20220

Affected Products

Undefined