8.6
CVE-2017-7914
- EPSS 12.58%
- Veröffentlicht 14.06.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012, 6.10-20140122, 7.00-20121012, 7.00-20130108, 7.00-20130325, 7.00-20130619, 7.00-20140128, 7.00-20140310, 7.00-20140429, 7.00-20140621, 7.00-20140729, 7.00-20141022, 8.00-20140730, and 8.00-20141023. There is no authorization check when connecting to the device, allowing an attacker remote access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version6.00-20140306
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version6.00.04
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version6.00.05
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version6.00.42
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version6.10-20140122
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version6.10.20121012
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version7.00-20121012
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version7.00-20130108
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version7.00-20130325
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version7.00-20130619
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version7.00-20140128
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version7.00-20140310
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version7.00-20140429
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version7.00-20140621
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version7.00-20140729
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version7.00-20141022
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version8.00-20140730
Rockwellautomation ≫ Panelview Plus 6 700-1500 Firmware Version8.00-20141023
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 12.58% | 0.937 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.6 | 3.9 | 4.7 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.