« Volver al listado

CVE-2017-9640

Estado: ModificadaMedia (6.3)—

A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-9640",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Automated Logic Corporation WebCTRL, i-VU, SiteScan",
          "versions": [
            {
              "status": "affected",
              "version": "Automated Logic Corporation WebCTRL, i-VU, SiteScan"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-08-25T19:29:00.410",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/100452",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-234-01",
      "tags": [
        "Mitigation",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.exploit-db.com/exploits/42543/",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.securityfocus.com/bid/100452",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-234-01",
      "tags": [
        "Mitigation",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/42543/",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software."
    },
    {
      "lang": "es",
      "value": "Se ha descubierto un problema de salto de directorio en Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web en versiones anteriores a la 6.5; ALC WebCTRL, SiteScan Web 6.1 y anteriores; ALC WebCTRL, i-Vu 6.0 y anteriores; ALC WebCTRL, i-Vu, SiteScan Web 5.5 y anteriores; y ALC WebCTRL, i-Vu, SiteScan Web 5.2 y anteriores. Un atacante autenticado podría ser capaz de sobrescribir archivos que se emplean para ejecutar código. Esta vulnerabilidad no afecta a la versión 6.5 del software."
    }
  ],
  "lastModified": "2026-06-17T01:28:38.387",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5948CDA4-5FE6-448B-9F64-D077F41DDF11",
              "versionEndIncluding": "5.2"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E829060A-3BA2-43ED-AAC9-E0E5008345DE",
              "versionEndIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F476895F-3AF0-4F96-8420-E57801B03F33",
              "versionEndIncluding": "6.0"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F6C18E1-2165-49FE-B351-56BF2B3142A1",
              "versionEndIncluding": "5.2"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "701AF14C-15DE-496A-8077-53D6BF3C80DC",
              "versionEndIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A35BFAD-0A53-438B-8A7A-78F92210DDE4",
              "versionEndIncluding": "6.1"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A41C3278-DB17-488C-BFEF-AA51B8289DD0",
              "versionEndIncluding": "5.2"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27E012C0-3E9B-484C-A697-B39DF43F0F69",
              "versionEndIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2A6E893-4D91-4D54-A831-B47F792FC6E6",
              "versionEndIncluding": "6.0"
            },
            {
              "criteria": "cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E912DDD9-081A-49A1-9CD5-9127B676A190",
              "versionEndIncluding": "6.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}