CVE-2017-6872

A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 21/tcp to access or alter historical measurement data stored on the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:ozw772_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ozw772:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:ozw672_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ozw672:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:30

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/99473 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/99473 - Third Party Advisory, VDB Entry
References () https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-563539.pdf - Vendor Advisory () https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-563539.pdf - Vendor Advisory

Information

Published : 2017-08-08 00:29

Updated : 2024-11-21 03:30


NVD link : CVE-2017-6872

Mitre link : CVE-2017-6872

CVE.ORG link : CVE-2017-6872


JSON object : View

Products Affected

siemens

  • ozw672
  • ozw772_firmware
  • ozw672_firmware
  • ozw772
CWE
CWE-306

Missing Authentication for Critical Function

CWE-668

Exposure of Resource to Wrong Sphere