CVE-2017-9967
published 2018-02-12CVE-2017-9967: A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as…
PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.39%
30.7th percentile
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | interactive_graphical_scada_system | <= 12.0 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric IGSS SCADA Software
cisa_ics·2018-02-13
Schneider Electric IGSS SCADA Software
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric IGSS SCADA Software
Last RevisedFebruary 13, 2018
Alert CodeICSA-18-044-02
## CVSS v3 7.0
ATTENTION: Locally exploitable/high skill level to exploit.
Vendor: Schneider Electric
Equipment: IGSS SCADA Software
Vulnerability: Security Misconfiguration
## AFFECTED PRODUCTS
Schneider Electric reports that the vulnerability affects the following IGSS SCADA Software products:
- IGSS SCADA Software V12 and all previous versions.
## IMPACT
Successful exploitation of this vulnerability could cause the device the attacker is accessing to crash or execute arbitrar
GHSA
GHSA-52rj-2977-r9p2: A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior
ghsa_unreviewed·2022-05-13
CVE-2017-9967 [HIGH] GHSA-52rj-2977-r9p2: A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-02-12
Published