Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-13997

Опубликовано: 03 окт. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:schneider-electric:wonderware_indusoft_web_studio:*:sp2:*:*:*:*:*:*
Версия до 8.0 (включая)
cpe:2.3:a:schneider-electric:wonderware_intouch:*:sp2:*:*:machine:*:*:*
Версия до 8.0 (включая)

EPSS

Процентиль: 81%
0.01586
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-306
CWE-306

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server.

CVSS3: 9.8
fstec
больше 8 лет назад

Уязвимость HMI/SCADA-систем Schneider Electric InTouch Machine Edition и InduSoft Web Studio, связанная с недостатками процедуры аутентификации, позволяющая нарушителю выполнить произвольные команды и получить полный контроль над сервером

EPSS

Процентиль: 81%
0.01586
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-306
CWE-306