cbcvebase.
CVE-2017-13997
published 2017-10-03

CVE-2017-13997: A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition…

PriorityP267critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
5.05%
91.3th percentile
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server.

Affected

2 ranges
VendorProductVersion rangeFixed in
schneider-electricwonderware_indusoft_web_studio<= 8.0
schneider-electricwonderware_intouch<= 8.0

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://download.indusoft.com/80.2.1/IWS80.2.1.zip
  • The vulnerability allows an unauthenticated remote client to trigger server-side script execution; detect unauthenticated HMI client-to-server script execution requests targeting InduSoft Web Studio or InTouch Machine Edition v8.0 SP2 or prior.
  • Monitor for high-privilege process spawning from InduSoft Web Studio or InTouch Machine Edition server processes, which may indicate successful exploitation of the missing authentication vulnerability.
  • CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication, no user interaction, and network-accessible attack surface — flag any inbound network connections to InduSoft Web Studio server ports from untrusted/external sources.
  • ·No known public exploits specifically target this vulnerability at time of advisory publication; threat may evolve.
  • ·The HMI client-to-server script execution channel is the attack vector; this feature should be access-controlled or disabled if not required.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.