7.5
CVE-2017-6021
- EPSS 0.45%
- Published 14.05.2018 14:29:00
- Last modified 21.11.2024 03:28:55
- Source ics-cert@hq.dhs.gov
- Teams watchlist Login
- Open Login
In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 R2 (build 77.5882) and prior, an attacker with network access to the ClearSCADA server can send specially crafted sequences of commands and data packets to the ClearSCADA server that can cause the ClearSCADA server process and ClearSCADA communications driver processes to terminate. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Data is provided by the National Vulnerability Database (NVD)
Aveva ≫ Clearscada Version <= 2010
Schneider-electric ≫ Clearscada Version2014 Updater1
Schneider-electric ≫ Clearscada Version2014 Updater1.1
Aveva ≫ Clearscada Version <= 2010
Schneider-electric ≫ Clearscada Version2015 Updater1
Schneider-electric ≫ Clearscada Version2015 Updater2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.45% | 0.609 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.