CVE-2017-13995
 
Severity Score
10.0
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does not properly authenticate users, which may allow a malicious attacker to access sensitive information such as HMI pages or modify PLC variables.
Se ha descubierto un problema de autenticación incorrecta en iniNet Solutions iniNet Webserver en todas las versiones anteriores a la V2.02.0111. El servidor web no autentica correctamente a los usuarios, lo que podría permitir que un atacante malicioso acceda a información sensible como las páginas HMI o que modifiquen variables PLC.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-08-30 CVE Reserved
- 2017-10-04 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100951 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-17-264-04 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Spidercontrol Search vendor "Spidercontrol" | Ininet Webserver Search vendor "Spidercontrol" for product "Ininet Webserver" | <= 2.02.0000 Search vendor "Spidercontrol" for product "Ininet Webserver" and version " <= 2.02.0000" | - |
Affected
|