CVE-2017-13992
 
Severity Score
8.1
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An Insufficient Entropy issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not utilize sufficiently random number generation for the web interface authentication mechanism, which could allow remote code execution.
Existe una vulnerabilidad relacionada con una entropía insuficiente en las versiones anteriores a 6.2.0 de LOYTEC LVIS-3ME. La aplicación no genera números lo suficientemente aleatorios para el mecanismo de autenticación de la interfaz web, lo que puede permitir que se ejecute código de manera remota.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-08-30 CVE Reserved
- 2017-10-05 CVE Published
- 2024-07-26 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-331: Insufficient Entropy
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100847 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-17-257-01 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Loytec Search vendor "Loytec" | Lvis-3me Firmware Search vendor "Loytec" for product "Lvis-3me Firmware" | <= 6.1.1 Search vendor "Loytec" for product "Lvis-3me Firmware" and version " <= 6.1.1" | - |
Affected
| in | Loytec Search vendor "Loytec" | Lvis-3me Search vendor "Loytec" for product "Lvis-3me" | - | - |
Safe
|