ID

VAR-201707-0391


CVE

CVE-2017-11349


TITLE

dataTaker DT8x dEX Vulnerable to program or schedule creation

Trust: 0.8

sources: JVNDB: JVNDB-2017-005931

DESCRIPTION

dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for uploading data. Thermo Fisher Scientific dataTaker DT8x dEX is a data acquisition recorder from Thermo Fisher Scientific, Australia. A security vulnerability exists in version 1.72.007 of Thermo Fisher Scientific dataTaker DT8x dEX. A remote attacker can exploit this vulnerability to obtain plaintext configuration information

Trust: 1.71

sources: NVD: CVE-2017-11349 // JVNDB: JVNDB-2017-005931 // VULHUB: VHN-101762

AFFECTED PRODUCTS

vendor:datatakermodel:dt8xscope:eqversion:1.72.007

Trust: 1.6

vendor:thermo fisher scientificmodel:datataker dt8xscope:eqversion:1.72.007

Trust: 0.8

sources: CNNVD: CNNVD-201707-763 // JVNDB: JVNDB-2017-005931 // NVD: CVE-2017-11349

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-11349
value: CRITICAL

Trust: 1.0

NVD: CVE-2017-11349
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201707-763
value: CRITICAL

Trust: 0.6

VULHUB: VHN-101762
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-11349
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-101762
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-11349
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-101762 // CNNVD: CNNVD-201707-763 // JVNDB: JVNDB-2017-005931 // NVD: CVE-2017-11349

PROBLEMTYPE DATA

problemtype:CWE-522

Trust: 1.1

problemtype:CWE-255

Trust: 0.9

sources: VULHUB: VHN-101762 // JVNDB: JVNDB-2017-005931 // NVD: CVE-2017-11349

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201707-763

TYPE

trust management problem

Trust: 0.6

sources: CNNVD: CNNVD-201707-763

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-005931

PATCH

title:DT8xurl:http://www.datataker.com/productsgeneral.php

Trust: 0.8

sources: JVNDB: JVNDB-2017-005931

EXTERNAL IDS

db:NVDid:CVE-2017-11349

Trust: 2.5

db:JVNDBid:JVNDB-2017-005931

Trust: 0.8

db:CNNVDid:CNNVD-201707-763

Trust: 0.7

db:VULHUBid:VHN-101762

Trust: 0.1

sources: VULHUB: VHN-101762 // CNNVD: CNNVD-201707-763 // JVNDB: JVNDB-2017-005931 // NVD: CVE-2017-11349

REFERENCES

url:https://nullku7.github.io/stuff/exposure/industrial/2017/05/02/thermofisher-datataker.html

Trust: 2.5

url:https://twitter.com/nullku7/status/859238295959609344

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-11349

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-11349

Trust: 0.8

sources: VULHUB: VHN-101762 // CNNVD: CNNVD-201707-763 // JVNDB: JVNDB-2017-005931 // NVD: CVE-2017-11349

SOURCES

db:VULHUBid:VHN-101762
db:CNNVDid:CNNVD-201707-763
db:JVNDBid:JVNDB-2017-005931
db:NVDid:CVE-2017-11349

LAST UPDATE DATE

2026-01-17T23:20:36.367000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-101762date:2019-10-03T00:00:00
db:CNNVDid:CNNVD-201707-763date:2019-10-23T00:00:00
db:JVNDBid:JVNDB-2017-005931date:2017-08-09T00:00:00
db:NVDid:CVE-2017-11349date:2026-01-16T19:28:18.943

SOURCES RELEASE DATE

db:VULHUBid:VHN-101762date:2017-07-17T00:00:00
db:CNNVDid:CNNVD-201707-763date:2017-07-25T00:00:00
db:JVNDBid:JVNDB-2017-005931date:2017-08-09T00:00:00
db:NVDid:CVE-2017-11349date:2017-07-17T13:18:21.237