CVE-2017-9940
published 2017-08-08CVE-2017-9940: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user…
PriorityP343high8.1CVSS 3.0
AVNACLPRLUINSUCHIHAN
EPSS
0.86%
54.2th percentile
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user account to read or write files on the file system of the SiPass integrated server over the network.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 0 < 3.13.0-123.172 | 3.13.0-123.172 |
| siemens | sipass_integrated | <= 2.65 | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9jh8-jxmj-8c4h: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2
ghsa_unreviewed·2022-05-13
CVE-2017-9940 [HIGH] CWE-269 GHSA-9jh8-jxmj-8c4h: A vulnerability was discovered in Siemens SiPass integrated (All versions before V2
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user account to read or write files on the file system of the SiPass integrated server over the network.
OSV
linux vulnerabilities
osv·2017-06-29·CVSS 7.0
CVE-2014-9940 linux vulnerabilities
linux vulnerabilities
USN 3335-1 fixed a vulnerability in the Linux kernel. However, that
fix introduced regressions for some Java applications. This update
addresses the issue. We apologize for the inconvenience.
It was discovered that a use-after-free vulnerability in the core voltage
regulator driver of the Linux kernel. A local attacker could use this to
cause a denial of service or possibly execute arbitrary code.
(CVE-2014-9940)
It was discovered that a buffer overflow existed in the trace subsystem in
the Linux kernel. A privileged local attacker could use this to execute
arbitrary code. (CVE-2017-0605)
Roee Hay discovered that the parallel port printer driver in the Linux
kernel did not properly bounds check passed arguments. A local attacker
with write access to the kernel com
CISA ICS
Siemens SiPass integrated
cisa_ics·2017-07-13
Siemens SiPass integrated
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SiPass integrated
Last RevisedJuly 13, 2017
Alert CodeICSA-17-194-01
## CVSS v3 9.8
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Siemens
Equipment: SiPass integrated
Vulnerabilities: Improper Authentication, Improper Privilege Management, Channel Accessible by Non-Endpoint, Storing Passwords in a Recoverable Format
## AFFECTED PRODUCTS
Siemens reports that the vulnerabilities affect the following SiPass integrated access control system:
- SiPass integrated: All versions prior to V2.70
## IMPACT
Successful exploitation of these vulnerabiliti
No detection rules found.
No public exploits indexed.
2017-08-08
Published