[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

95906

 
 

909

 
 

77986

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2017-13997

Date: (C)2017-10-04   (M)2017-10-12
 
CVSS Score: 6.5Access Vector:
Exploitability Subscore: Access Complexity:
Impact Subscore: Authentication:
 Confidentiality:
 Integrity:
 Availability:











A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server.

Reference:
BID-100952
https://ics-cert.us-cert.gov/advisories/ICSA-17-264-01

© 2013 SecPod Technologies