Lucene search

K
cvelistMitreCVELIST:CVE-2017-17974
HistoryDec 29, 2017 - 9:00 p.m.

CVE-2017-17974

2017-12-2921:00:00
mitre
www.cve.org
5
cve-2017-17974
remote attackers
sensitive information
httpserv 00002
script 02
administrative access

AI Score

9.3

Confidence

High

EPSS

0.015

Percentile

87.0%

BA SYSTEMS BAS Web on BAS920 devices (with Firmware 01.01.00*, HTTPserv 00002, and Script 02.*) and ISC2000 devices allows remote attackers to obtain sensitive information via a request for isc/get_sid_js.aspx or isc/get_sid.aspx, as demonstrated by obtaining administrative access by subsequently using the credential information for the Supervisor/Administrator account.

AI Score

9.3

Confidence

High

EPSS

0.015

Percentile

87.0%

Related for CVELIST:CVE-2017-17974