7.5
CVE-2017-6021
- EPSS 0.45%
- Veröffentlicht 14.05.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:28:55
- Quelle ics-cert@hq.dhs.gov
- Teams Watchlist Login
- Unerledigt Login
In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 R2 (build 77.5882) and prior, an attacker with network access to the ClearSCADA server can send specially crafted sequences of commands and data packets to the ClearSCADA server that can cause the ClearSCADA server process and ClearSCADA communications driver processes to terminate. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aveva ≫ Clearscada Version <= 2010
Schneider-electric ≫ Clearscada Version2014 Updater1
Schneider-electric ≫ Clearscada Version2014 Updater1.1
Aveva ≫ Clearscada Version <= 2010
Schneider-electric ≫ Clearscada Version2015 Updater1
Schneider-electric ≫ Clearscada Version2015 Updater2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.45% | 0.609 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.