Lucene search

K
nvd[email protected]NVD:CVE-2017-9644
HistoryAug 25, 2017 - 7:29 p.m.

CVE-2017-9644

2017-08-2519:29:00
CWE-428
web.nvd.nist.gov
2

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

18.3%

An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.

Affected configurations

Nvd
Node
automatedlogici-vuRange5.2
OR
automatedlogici-vuRange5.5
OR
automatedlogici-vuRange6.0
OR
automatedlogici-vuRange6.5
OR
automatedlogicsitescan_webRange5.2
OR
automatedlogicsitescan_webRange5.5
OR
automatedlogicsitescan_webRange6.1
OR
automatedlogicsitescan_webRange6.5
OR
carrierautomatedlogic_webctrlRange5.2
OR
carrierautomatedlogic_webctrlRange5.5
OR
carrierautomatedlogic_webctrlRange6.0
OR
carrierautomatedlogic_webctrlRange6.1
OR
carrierautomatedlogic_webctrlRange6.5
VendorProductVersionCPE
automatedlogici-vu*cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:*
automatedlogicsitescan_web*cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:*
carrierautomatedlogic_webctrl*cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

18.3%