CVE-2017-9640
Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.
Se ha descubierto un problema de salto de directorio en Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web en versiones anteriores a la 6.5; ALC WebCTRL, SiteScan Web 6.1 y anteriores; ALC WebCTRL, i-Vu 6.0 y anteriores; ALC WebCTRL, i-Vu, SiteScan Web 5.5 y anteriores; y ALC WebCTRL, i-Vu, SiteScan Web 5.2 y anteriores. Un atacante autenticado podría ser capaz de sobrescribir archivos que se emplean para ejecutar código. Esta vulnerabilidad no afecta a la versión 6.5 del software.
Automated Logic WebCTRL version 6.1 suffers from path traversal and arbitrary file write vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-06-14 CVE Reserved
- 2017-08-23 CVE Published
- 2023-08-05 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100452 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-17-234-01 | Mitigation |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/42543 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Automatedlogic Search vendor "Automatedlogic" | I-vu Search vendor "Automatedlogic" for product "I-vu" | <= 5.2 Search vendor "Automatedlogic" for product "I-vu" and version " <= 5.2" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | I-vu Search vendor "Automatedlogic" for product "I-vu" | <= 5.5 Search vendor "Automatedlogic" for product "I-vu" and version " <= 5.5" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | I-vu Search vendor "Automatedlogic" for product "I-vu" | <= 6.0 Search vendor "Automatedlogic" for product "I-vu" and version " <= 6.0" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | Sitescan Web Search vendor "Automatedlogic" for product "Sitescan Web" | <= 5.2 Search vendor "Automatedlogic" for product "Sitescan Web" and version " <= 5.2" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | Sitescan Web Search vendor "Automatedlogic" for product "Sitescan Web" | <= 5.5 Search vendor "Automatedlogic" for product "Sitescan Web" and version " <= 5.5" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | Sitescan Web Search vendor "Automatedlogic" for product "Sitescan Web" | <= 6.1 Search vendor "Automatedlogic" for product "Sitescan Web" and version " <= 6.1" | - |
Affected
| ||||||
Carrier Search vendor "Carrier" | Automatedlogic Webctrl Search vendor "Carrier" for product "Automatedlogic Webctrl" | <= 5.2 Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 5.2" | - |
Affected
| ||||||
Carrier Search vendor "Carrier" | Automatedlogic Webctrl Search vendor "Carrier" for product "Automatedlogic Webctrl" | <= 5.5 Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 5.5" | - |
Affected
| ||||||
Carrier Search vendor "Carrier" | Automatedlogic Webctrl Search vendor "Carrier" for product "Automatedlogic Webctrl" | <= 6.0 Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 6.0" | - |
Affected
| ||||||
Carrier Search vendor "Carrier" | Automatedlogic Webctrl Search vendor "Carrier" for product "Automatedlogic Webctrl" | <= 6.1 Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 6.1" | - |
Affected
|