7.8
CVE-2017-9967
- EPSS 0.09%
- Veröffentlicht 12.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:37:16
- Quelle cybersecurity@se.com
- Teams Watchlist Login
- Unerledigt Login
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Interactive Graphical Scada System Version <= 12.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.232 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|