CVE-2017-13997
published 2017-10-03CVE-2017-13997: A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition…
PriorityP267critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
5.05%
91.3th percentile
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | wonderware_indusoft_web_studio | <= 8.0 | — |
| schneider-electric | wonderware_intouch | <= 8.0 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability allows an unauthenticated remote client to trigger server-side script execution; detect unauthenticated HMI client-to-server script execution requests targeting InduSoft Web Studio or InTouch Machine Edition v8.0 SP2 or prior. ↗
- →Monitor for high-privilege process spawning from InduSoft Web Studio or InTouch Machine Edition server processes, which may indicate successful exploitation of the missing authentication vulnerability. ↗
- →CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication, no user interaction, and network-accessible attack surface — flag any inbound network connections to InduSoft Web Studio server ports from untrusted/external sources. ↗
- ·No known public exploits specifically target this vulnerability at time of advisory publication; threat may evolve. ↗
- ·The HMI client-to-server script execution channel is the attack vector; this feature should be access-controlled or disabled if not required. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mpcf-5x9h-p6p7: A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8
ghsa_unreviewed·2022-05-13
CVE-2017-13997 [CRITICAL] CWE-306 GHSA-mpcf-5x9h-p6p7: A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server.
CISA ICS
Schneider Electric InduSoft Web Studio, InTouch Machine Edition
cisa_ics·2017-09-21
Schneider Electric InduSoft Web Studio, InTouch Machine Edition
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric InduSoft Web Studio, InTouch Machine Edition
Last RevisedSeptember 21, 2017
Alert CodeICSA-17-264-01
## CVSS v3 9.8
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Schneider Electric
Equipment: InduSoft Web Studio, InTouch Machine Edition
Vulnerability: Missing Authentication for Critical Function
## AFFECTED PRODUCTS
Schneider Electric reports that the vulnerability affects the following InduSoft Web Studio products:
- InduSoft Web Studio v8.0 SP2 or prior, and
- InTouch Machine Edition v8.0 SP2 or prior.
## IMPACT
Successful expl
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-03
Published