peter bassill · operator
$ cve CVE-2017-6869 JSON

CVE-2017-6869

9.8
CRITICAL · CVSS 3.0 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web server by sending specially crafted network packets to port 443/TCP or port 80/TCP.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.98% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2017-08-08
Last modified2026-06-17

Affected (1)

VendorProduct
siemensviewport for web office portal

References

→ the Explorer  ·  watch your stack  ·  NVD