← Vulnerability feed

Vulnerability record · CVE-2017-9822 · published 20 July 2017

CVE-2017-9822: DNN (DotNetNuke) cookie deserialization remote code execution

DDnnsoftware · Dotnetnuke

DNN (DotNetNuke) before 9.1.1 deserializes attacker-controlled cookie data, allowing remote code execution. The flaw is a code injection (CWE-94) reachable over the network, and it is listed in CISA's Known Exploited Vulnerabilities catalog with documented ransomware campaign use.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 Known ransomware use EPSS 95% · top 0.1% CWE-94 · Code injection
8.8CVSS 3.1 base score, v2 6.5
95%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is a network-reachable remote code execution flaw listed in CISA KEV with known ransomware use and a very high EPSS score.

What it is

DNN (DotNetNuke) before 9.1.1 deserializes attacker-controlled cookie data, allowing remote code execution. The flaw is a code injection (CWE-94) reachable over the network, and it is listed in CISA's Known Exploited Vulnerabilities catalog with documented ransomware campaign use.

Impact

An attacker who can reach the site can execute arbitrary code on the server, leading to full compromise of confidentiality, integrity and availability.

Attack surface

Reached over the network via a crafted cookie; the CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N). No further detail on the exact endpoint is given in the record.

Exploitation

CISA KEV lists it as exploited, including known ransomware campaign use, and EPSS is very high (0.94789, 99.855th percentile). Public exploit code is referenced (Packet Storm), so exploitation is active and well understood.

What to do

  • Upgrade DNN to 9.1.1 or later per vendor instructions.
  • If immediate upgrade is not possible, restrict or block external access to the DNN site and apply vendor-recommended workarounds.
  • Rotate any secrets, machine keys and credentials that may have been exposed on affected hosts.
  • Monitor and restrict outbound traffic from DNN servers to limit post-exploitation activity.
  • Verify no unauthorized web shells or modified files remain after patching.

Detection

  • Inspect web server and application logs for anomalous or malformed cookie values sent to DNN endpoints.
  • Hunt for unexpected child processes spawned by the web server (w3wp.exe) or unusual command execution.
  • Monitor for new or modified files under the DNN web root, especially executable or script files.
  • Alert on outbound connections from DNN hosts to unfamiliar external addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-9822 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "DotNetNuke (DNN) Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-9822 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2018-15811DNN (DotNetNuke) weak encryption of input parametersDNN (DotNetNuke) versions 9.2 through 9.2.1 use a weak encryption algorithm to protect input parameters. Because the protection is inadequate, data t…KEVEPSS 76%analysed7.5CVE-2018-18325DNN (DotNetNuke) weak encryption of input parametersDNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters, and the issue persists because the fix for C…KEVEPSS 74%analysed10.0CVE-2006-3601Dnnsoftware dotnetnuke vulnerability** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileg…EPSS 2.5%9.8CVE-2025-64095Dnnsoftware dotnetnuke unrestricted file upload vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML edito…EPSS 45%9.8CVE-2015-2794DotNetNuke install wizard allows unauthenticated reinstall and SuperUser takeoverThe installation wizard in DotNetNuke (DNN) before 7.4.1 can be reached directly at Install/InstallWizard.aspx and used to reinstall the application.…EPSS 75%analysed9.0CVE-2025-59545Dnnsoftware dotnetnuke cross-site scripting vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt mod…EPSS 0.49%8.8CVE-2025-52487Dnnsoftware dotnetnuke incorrect authorization vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN…EPSS 0.35%8.8CVE-2020-5187Dnnsoftware dotnetnuke path traversal vulnerabilityDNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2017-9822), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.