« Volver al listado

CVE-2017-9644

Estado: ModificadaAlta (7)—

An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-9644",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Automated Logic Corporation WebCTRL, i-VU, SiteScan",
          "versions": [
            {
              "status": "affected",
              "version": "Automated Logic Corporation WebCTRL, i-VU, SiteScan"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-08-25T19:29:00.457",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/100454",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-234-01",
      "tags": [
        "Mitigation",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.exploit-db.com/exploits/42542/",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.securityfocus.com/bid/100454",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-234-01",
      "tags": [
        "Mitigation",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/42542/",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-428"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-428"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema de ruta de búsqueda o elemento sin comillas en Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 y anteriores; ALC WebCTRL, SiteScan Web 6.1 y anteriores; ALC WebCTRL, i-Vu 6.0 y anteriores; ALC WebCTRL, i-Vu, SiteScan Web 5.5 y anteriores; y ALC WebCTRL, i-Vu, SiteScan Web 5.2 y anteriores. Una vulnerabilidad de ruta de búsqueda sin comillas podría permitir que un atacante local sin privilegios cambie archivos en el directorio de instalación y ejecute código arbitrario con privilegios elevados."
    }
  ],
  "lastModified": "2026-06-17T01:28:38.647",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5948CDA4-5FE6-448B-9F64-D077F41DDF11",
              "versionEndIncluding": "5.2"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E829060A-3BA2-43ED-AAC9-E0E5008345DE",
              "versionEndIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F476895F-3AF0-4F96-8420-E57801B03F33",
              "versionEndIncluding": "6.0"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "865ECF73-F257-4A48-831E-4A542ADA4BD4",
              "versionEndIncluding": "6.5"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F6C18E1-2165-49FE-B351-56BF2B3142A1",
              "versionEndIncluding": "5.2"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "701AF14C-15DE-496A-8077-53D6BF3C80DC",
              "versionEndIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A35BFAD-0A53-438B-8A7A-78F92210DDE4",
              "versionEndIncluding": "6.1"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D602FF0F-8AFE-4815-BFA0-623DE28D26FC",
              "versionEndIncluding": "6.5"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A41C3278-DB17-488C-BFEF-AA51B8289DD0",
              "versionEndIncluding": "5.2"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27E012C0-3E9B-484C-A697-B39DF43F0F69",
              "versionEndIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2A6E893-4D91-4D54-A831-B47F792FC6E6",
              "versionEndIncluding": "6.0"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E912DDD9-081A-49A1-9CD5-9127B676A190",
              "versionEndIncluding": "6.1"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "292B6AC3-89A7-4E81-946A-7C0FED0DF79D",
              "versionEndIncluding": "6.5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}