CVE-2017-9640
CVE-2017-9640
Vexday Risk Score
23Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 8.5%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
22 Aug 2017Public PoC
25 Aug 2017Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.
Affected products
n/a · Automated Logic Corporation WebCTRL, i-VU, SiteScanpublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/42543/unverifiedexploitdbwww.exploit-db.com/exploits/42543unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →