CVE-2017-9661
 
Severity Score
7.0
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An Uncontrolled Search Path Element issue was discovered in SIMPlight SCADA Software version 4.3.0.27 and prior. The uncontrolled search path element vulnerability has been identified, which may allow an attacker to place a malicious DLL file within the search path resulting in execution of arbitrary code.
Se ha descubierto un problema de elemento de ruta de búsqueda no controlado en SIMPlight SCADA Software versión 4.3.0.27 y anteriores. Se ha identificado la vulnerabilidad de elemento de ruta de búsqueda no controlado, lo que podría permitir que un atacante coloque un archivo DLL malicioso en la ruta de búsqueda, desembocando en la ejecución de código arbitrario.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-06-14 CVE Reserved
- 2017-08-14 CVE Published
- 2024-03-17 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-427: Uncontrolled Search Path Element
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100263 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-17-222-01 | Mitigation |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Simplight Search vendor "Simplight" | Scada Search vendor "Simplight" for product "Scada" | <= 4.3.0.27 Search vendor "Simplight" for product "Scada" and version " <= 4.3.0.27" | - |
Affected
|