CVE-2017-13997
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server.
Se descubrió un problema de ausencia de autenticación para una función crítica en Schneider Electric InduSoft Web Studio v8.0 SP2 o anteriores y en InTouch Machine Edition v8.0 SP2 o anteriores. InduSoft Web Studio proporciona la capacidad para que un cliente HMI dé lugar a la ejecución de un script en el servidor para realizar cálculos o acciones personalizados. Una entidad maliciosa remota podría omitir la autenticación del servidor y desencadenar la ejecución de un comando arbitrario. El comando se ejecuta con privilegios elevados y podría desembocar en un compromiso del servidor por completo.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-30 CVE Reserved
- 2017-10-02 CVE Published
- 2024-05-05 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100952 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-17-264-01 | Mitigation |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Wonderware Indusoft Web Studio Search vendor "Schneider-electric" for product "Wonderware Indusoft Web Studio" | <= 8.0 Search vendor "Schneider-electric" for product "Wonderware Indusoft Web Studio" and version " <= 8.0" | sp2 |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Wonderware Intouch Search vendor "Schneider-electric" for product "Wonderware Intouch" | <= 8.0 Search vendor "Schneider-electric" for product "Wonderware Intouch" and version " <= 8.0" | sp2, machine |
Affected
|