9.8

CVE-2017-6041

An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C; M3210 terminal associated with the same systems as the M3000 terminal identified above; M3000 desktop software associated with the same systems as the M3000 terminal identified above; MAC4 controller associated with the same systems as the M3000 terminal identified above; SensorX23 X-ray machine; SensorX25 X-ray machine; and MWS2 weighing system. This vulnerability allows an attacker to modify the operation and upload firmware changes without detection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MarelA320 Firmware Version-
   MarelA320 Version-
MarelA325 Firmware Version-
   MarelA325 Version-
MarelA371 Firmware Version-
   MarelA371 Version-
MarelA520 Master Firmware Version-
   MarelA520 Master Version-
MarelA520 Slave Firmware Version-
   MarelA520 Slave Version-
MarelA530 Firmware Version-
   MarelA530 Version-
MarelA542 Firmware Version-
   MarelA542 Version-
MarelA571 Firmware Version-
   MarelA571 Version-
MarelCheck Bin Grader Firmware Version-
   MarelCheck Bin Grader Version-
MarelFlowlineqc T376 Firmware Version-
   MarelFlowlineqc T376 Version-
MarelIpm3 Dual Cam Firmware Version132
   MarelIpm3 Dual Cam Version-
MarelIpm3 Dual Cam Firmware Version139
   MarelIpm3 Dual Cam Version-
MarelIpm3 Dual Cam Firmware Version132
   MarelIpm3 Dual Cam Version-
MarelP520 Firmware Version-
   MarelP520 Version-
MarelP574 Firmware Version-
   MarelP574 Version-
MarelSensorx23 Qc Slave Firmware Version-
   MarelSensorx23 Qc Slave Version-
MarelSpeed Batcher Firmware Version-
   MarelSpeed Batcher Version-
MarelT374 Firmware Version-
   MarelT374 Version-
MarelT377 Firmware Version-
   MarelT377 Version-
MarelV36 Firmware Version-
   MarelV36 Version-
MarelV36b Firmware Version-
   MarelV36b Version-
MarelV36c Firmware Version-
   MarelV36c Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.677
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.