Vulnerability CVE-2017-9631


Published: 2017-07-07

Description:
A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The null pointer dereference vulnerability could allow an attacker to crash the logger process, causing a denial of service for logging and log-viewing (applications that use the Wonderware ArchestrA Logger continue to run when the Wonderware ArchestrA Logger service is unavailable).

Type:

CWE-476

(NULL Pointer Dereference)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Schneider electric -> Wonderware archestra logger 

 References:
http://software.schneider-electric.com/pdf/security-bulletin/lfsec00000116/
http://www.securityfocus.com/bid/99488
http://www.securitytracker.com/id/1038836
https://ics-cert.us-cert.gov/advisories/ICSA-17-187-04

Copyright 2024, cxsecurity.com

 

Back to Top