peter bassill · operator
$ cve CVE-2017-9640 JSON

CVE-2017-9640 EXPLOIT

6.3
MEDIUM · CVSS 3.0 · EPSS 8.5% (pctl 95)

Patch early

A public exploit exists.

Description

A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.

Scoring

CVSS6.3 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS8.45% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2017-08-25
Last modified2026-06-17

Affected (3)

VendorProduct
automatedlogici-vu
automatedlogicsitescan web
carrierautomatedlogic webctrl

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD