CVE-2017-7440

6.5
MEDIUMCVSS v3.1 Base Score
0.93%
LOW RiskEPSS (59th percentile)

Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.

Published: 5/2/2017
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CVSS v2 Score

4.3

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Score (Exploitation Probability)

0.93%LOW Exploitation Risk
59th percentile

This vulnerability has a 0.93% probability of being exploited in the next 30 days, ranking higher than 59% of all scored CVEs.

CWE Classification

Advertisement