A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. A malicious user may be able to gain access to configuration information that should be restricted.
References
Link | Resource |
---|---|
http://search.abb.com/library/Download.aspx?DocumentID=9AKK107045A1977&LanguageCode=en&DocumentPartId=&Action=Launch | Vendor Advisory |
http://www.securityfocus.com/bid/99558 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-17-192-03 | Third Party Advisory US Government Resource |
http://search.abb.com/library/Download.aspx?DocumentID=9AKK107045A1977&LanguageCode=en&DocumentPartId=&Action=Launch | Vendor Advisory |
http://www.securityfocus.com/bid/99558 | Third Party Advisory VDB Entry |
https://ics-cert.us-cert.gov/advisories/ICSA-17-192-03 | Third Party Advisory US Government Resource |
Configurations
History
21 Nov 2024, 03:32
Type | Values Removed | Values Added |
---|---|---|
References | () http://search.abb.com/library/Download.aspx?DocumentID=9AKK107045A1977&LanguageCode=en&DocumentPartId=&Action=Launch - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/99558 - Third Party Advisory, VDB Entry | |
References | () https://ics-cert.us-cert.gov/advisories/ICSA-17-192-03 - Third Party Advisory, US Government Resource |
Information
Published : 2017-08-07 08:29
Updated : 2024-11-21 03:32
NVD link : CVE-2017-7916
Mitre link : CVE-2017-7916
CVE.ORG link : CVE-2017-7916
JSON object : View
Products Affected
abb
- vsn300_for_react
- vsn300
- vsn300_firmware
- vsn300_for_react_firmware