« Volver al listado

CVE-2017-5176

Estado: ModificadaAlta (7)—

A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and 9328-CCWDEVPTE; and Connected Components Workbench - Free Standard Edition (All Supported Languages), v9.01.00 and earlier. Certain DLLs included with versions of CCW software can be potentially hijacked to allow an attacker to gain rights to a victim's affected personal computer. Such access rights can be at the same or potentially higher level of privileges as the compromised user account, including and up to computer administrator privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-5176",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 1.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Rockwell Automation Connected Components Workbench",
          "versions": [
            {
              "status": "affected",
              "version": "Rockwell Automation Connected Components Workbench"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-05-19T03:29:00.293",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/97000",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-047-01",
      "tags": [
        "Patch",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.securityfocus.com/bid/97000",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-047-01",
      "tags": [
        "Patch",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-427"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-427"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and 9328-CCWDEVPTE; and Connected Components Workbench - Free Standard Edition (All Supported Languages), v9.01.00 and earlier. Certain DLLs included with versions of CCW software can be potentially hijacked to allow an attacker to gain rights to a victim's affected personal computer. Such access rights can be at the same or potentially higher level of privileges as the compromised user account, including and up to computer administrator privileges."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema de secuestro de DLL en Connected Components Workbench (CCW) de Rockwell Automation. Están afectadas las siguientes versiones: Connected Components Workbench - Developer Edition, versión v9.01.00 y anteriores a: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CC y Connected Components Workbench - Edición Estándar Gratuita (todos los idiomas compatibles), versión v9.01.00 y anteriores. Ciertos bibliotecas DLL incluidas con las versiones de software de CCW pueden ser secuestradas para permitir a un atacante alcanzar derechos sobre la computadora personal afectada de la víctima. Dichos derechos de acceso pueden estar en el mismo nivel de privilegios o potencialmente en un nivel más alto al de la cuenta de usuario comprometida, incluyendo los privilegios de administrador de computadora."
    }
  ],
  "lastModified": "2026-06-17T01:20:05.993",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rockwellautomation:connected_components_workbench:*:*:*:*:developer:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D30E0FF5-DFC8-4A9E-AC5E-A989607E2419",
              "versionEndIncluding": "9.01.00"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevdee:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "669BA851-4DD0-498B-8775-4C9529CAF06C"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevene:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "589025A2-B3B1-4FFC-A6F2-9D6E3A976E3E"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevese:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "49295F0C-B90A-46BF-AC22-723743237A3D"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevfre:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5B41A881-8DAA-43E3-934E-4500C8815666"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevite:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3D2366F9-803F-433A-8712-1E328D03FFAF"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevpte:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "68B1539D-19C2-4048-8904-C0B6D60E34D6"
            },
            {
              "criteria": "cpe:2.3:h:rockwellautomation:9328-ccwdevzhe:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C5654863-5B85-4EE3-96A2-8624407BD9FC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rockwellautomation:connected_components_workbench:*:*:*:*:free_standard:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AE5B4DF-E10A-42DB-B9F3-E9D292281235",
              "versionEndIncluding": "9.01.00"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}