CVE-2017-7968
published 2017-05-19CVE-2017-7968: An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
34.9th percentile
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | wonderware_indusoft_web_studio | <= 8.0 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Wonderware InduSoft Web Studio
cisa_ics·2017-05-18
Schneider Electric Wonderware InduSoft Web Studio
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Wonderware InduSoft Web Studio
Last RevisedMay 18, 2017
Alert CodeICSA-17-138-02
## CVSS v3 7.3
ATTENTION: Low skill level to exploit.
Vendor: Schneider Electric
Equipment: Wonderware InduSoft Web Studio
Vulnerability: Incorrect Default Permissions
## AFFECTED PRODUCTS
The following versions of Schneider Electric’s Wondeware InduSoft Web Studio are affected:
- Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions.
## IMPACT
Successful exploitation of this vulnerability could allow an authenticated user to escalate his or her privileges.
## MI
GHSA
GHSA-366x-vf96-q5vp: An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8
ghsa_unreviewed·2022-05-13
CVE-2017-7968 [HIGH] CWE-276 GHSA-366x-vf96-q5vp: An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2017-090-02http://www.securityfocus.com/bid/98544https://ics-cert.us-cert.gov/advisories/ICSA-17-138-02http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2017-090-02http://www.securityfocus.com/bid/98544https://ics-cert.us-cert.gov/advisories/ICSA-17-138-02
2017-05-19
Published