CVE-2017-13997
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.05%
- Percentil entre todas las CVEs puntuadas: 92
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-306
- CWE-306
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-13997",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "n/a",
"product": "Schneider Electric InduSoft Web Studio, InTouch Machine Edition",
"versions": [
{
"status": "affected",
"version": "Schneider Electric InduSoft Web Studio, InTouch Machine Edition"
}
]
}
]
}
],
"published": "2017-10-03T01:29:01.857",
"references": [
{
"url": "http://www.securityfocus.com/bid/100952",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-264-01",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://www.securityfocus.com/bid/100952",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-264-01",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server."
},
{
"lang": "es",
"value": "Se descubrió un problema de ausencia de autenticación para una función crítica en Schneider Electric InduSoft Web Studio v8.0 SP2 o anteriores y en InTouch Machine Edition v8.0 SP2 o anteriores. InduSoft Web Studio proporciona la capacidad para que un cliente HMI dé lugar a la ejecución de un script en el servidor para realizar cálculos o acciones personalizados. Una entidad maliciosa remota podría omitir la autenticación del servidor y desencadenar la ejecución de un comando arbitrario. El comando se ejecuta con privilegios elevados y podría desembocar en un compromiso del servidor por completo."
}
],
"lastModified": "2026-06-17T01:05:24.833",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:schneider-electric:wonderware_indusoft_web_studio:*:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "909E4BF0-FD67-4F8B-B577-57E8E5F7A686",
"versionEndIncluding": "8.0"
},
{
"criteria": "cpe:2.3:a:schneider-electric:wonderware_intouch:*:sp2:*:*:machine:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F51870FA-9C46-4C8B-83B0-3C32B0722581",
"versionEndIncluding": "8.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}