// For flags

CVE-2017-9640

Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write

Severity Score

6.3
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.

Se ha descubierto un problema de salto de directorio en Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web en versiones anteriores a la 6.5; ALC WebCTRL, SiteScan Web 6.1 y anteriores; ALC WebCTRL, i-Vu 6.0 y anteriores; ALC WebCTRL, i-Vu, SiteScan Web 5.5 y anteriores; y ALC WebCTRL, i-Vu, SiteScan Web 5.2 y anteriores. Un atacante autenticado podría ser capaz de sobrescribir archivos que se emplean para ejecutar código. Esta vulnerabilidad no afecta a la versión 6.5 del software.

Automated Logic WebCTRL version 6.1 suffers from path traversal and arbitrary file write vulnerabilities.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-06-14 CVE Reserved
  • 2017-08-23 CVE Published
  • 2023-08-05 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Automatedlogic
Search vendor "Automatedlogic"
I-vu
Search vendor "Automatedlogic" for product "I-vu"
<= 5.2
Search vendor "Automatedlogic" for product "I-vu" and version " <= 5.2"
-
Affected
Automatedlogic
Search vendor "Automatedlogic"
I-vu
Search vendor "Automatedlogic" for product "I-vu"
<= 5.5
Search vendor "Automatedlogic" for product "I-vu" and version " <= 5.5"
-
Affected
Automatedlogic
Search vendor "Automatedlogic"
I-vu
Search vendor "Automatedlogic" for product "I-vu"
<= 6.0
Search vendor "Automatedlogic" for product "I-vu" and version " <= 6.0"
-
Affected
Automatedlogic
Search vendor "Automatedlogic"
Sitescan Web
Search vendor "Automatedlogic" for product "Sitescan Web"
<= 5.2
Search vendor "Automatedlogic" for product "Sitescan Web" and version " <= 5.2"
-
Affected
Automatedlogic
Search vendor "Automatedlogic"
Sitescan Web
Search vendor "Automatedlogic" for product "Sitescan Web"
<= 5.5
Search vendor "Automatedlogic" for product "Sitescan Web" and version " <= 5.5"
-
Affected
Automatedlogic
Search vendor "Automatedlogic"
Sitescan Web
Search vendor "Automatedlogic" for product "Sitescan Web"
<= 6.1
Search vendor "Automatedlogic" for product "Sitescan Web" and version " <= 6.1"
-
Affected
Carrier
Search vendor "Carrier"
Automatedlogic Webctrl
Search vendor "Carrier" for product "Automatedlogic Webctrl"
<= 5.2
Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 5.2"
-
Affected
Carrier
Search vendor "Carrier"
Automatedlogic Webctrl
Search vendor "Carrier" for product "Automatedlogic Webctrl"
<= 5.5
Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 5.5"
-
Affected
Carrier
Search vendor "Carrier"
Automatedlogic Webctrl
Search vendor "Carrier" for product "Automatedlogic Webctrl"
<= 6.0
Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 6.0"
-
Affected
Carrier
Search vendor "Carrier"
Automatedlogic Webctrl
Search vendor "Carrier" for product "Automatedlogic Webctrl"
<= 6.1
Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 6.1"
-
Affected