« Volver al listado

CVE-2017-9650

Estado: ModificadaAlta (7.8)—

An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-9650",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Automated Logic Corporation WebCTRL, i-VU, SiteScan",
          "versions": [
            {
              "status": "affected",
              "version": "Automated Logic Corporation WebCTRL, i-VU, SiteScan"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-08-25T19:29:00.487",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/100452",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-234-01",
      "tags": [
        "Mitigation",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.exploit-db.com/exploits/42544/",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.securityfocus.com/bid/100452",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-234-01",
      "tags": [
        "Mitigation",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/42544/",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema de carga de archivos sin restricciones con tipos peligrosos en Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 y anteriores; ALC WebCTRL, SiteScan Web 6.1 y anteriores; ALC WebCTRL, i-Vu 6.0 y anteriores; ALC WebCTRL, i-Vu, SiteScan Web 5.5 y anteriores; y ALC WebCTRL, i-Vu, SiteScan Web 5.2 y anteriores. Un atacante autenticado podría ser capaz de subir un archivo malicioso que permita la ejecución de código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T01:28:39.387",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5948CDA4-5FE6-448B-9F64-D077F41DDF11",
              "versionEndIncluding": "5.2"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E829060A-3BA2-43ED-AAC9-E0E5008345DE",
              "versionEndIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F476895F-3AF0-4F96-8420-E57801B03F33",
              "versionEndIncluding": "6.0"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "865ECF73-F257-4A48-831E-4A542ADA4BD4",
              "versionEndIncluding": "6.5"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F6C18E1-2165-49FE-B351-56BF2B3142A1",
              "versionEndIncluding": "5.2"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "701AF14C-15DE-496A-8077-53D6BF3C80DC",
              "versionEndIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A35BFAD-0A53-438B-8A7A-78F92210DDE4",
              "versionEndIncluding": "6.1"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D602FF0F-8AFE-4815-BFA0-623DE28D26FC",
              "versionEndIncluding": "6.5"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A41C3278-DB17-488C-BFEF-AA51B8289DD0",
              "versionEndIncluding": "5.2"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27E012C0-3E9B-484C-A697-B39DF43F0F69",
              "versionEndIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2A6E893-4D91-4D54-A831-B47F792FC6E6",
              "versionEndIncluding": "6.0"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E912DDD9-081A-49A1-9CD5-9127B676A190",
              "versionEndIncluding": "6.1"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "292B6AC3-89A7-4E81-946A-7C0FED0DF79D",
              "versionEndIncluding": "6.5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}