ID

VAR-201707-0991


CVE

CVE-2017-7919


TITLE

Newport XPS-Cx and XPS-Qx Vulnerabilities bypassing authentication

Trust: 0.8

sources: JVNDB: JVNDB-2017-006078

DESCRIPTION

An Improper Authentication issue was discovered in Newport XPS-Cx and XPS-Qx. An attacker may bypass authentication by accessing a specific uniform resource locator (URL). NewportXPS-Cx is a device controller from Newport, USA, and XPS-Qx is another version of it. There are licensing issues in NewportXPS-Cx and XPS-Qx. This may lead to further attacks. All versions of XPS-Cx,XPS-Qx are vulnerable

Trust: 2.7

sources: NVD: CVE-2017-7919 // JVNDB: JVNDB-2017-006078 // CNVD: CNVD-2017-15913 // BID: 99291 // IVD: b40e48ff-a5af-4308-9fd6-615f0a36d9ae // VULHUB: VHN-116122

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: b40e48ff-a5af-4308-9fd6-615f0a36d9ae // CNVD: CNVD-2017-15913

AFFECTED PRODUCTS

vendor:newportmodel:xps-qxscope:eqversion: -

Trust: 1.6

vendor:newportmodel:xps-cxscope:eqversion: -

Trust: 1.6

vendor:newportmodel:xps-cxscope: - version: -

Trust: 1.4

vendor:newportmodel:xps-qxscope: - version: -

Trust: 1.4

vendor:newportmodel:xps-qxscope:eqversion:0

Trust: 0.3

vendor:newportmodel:xps-cxscope:eqversion:0

Trust: 0.3

vendor:xps cxmodel: - scope:eqversion: -

Trust: 0.2

vendor:xps qxmodel: - scope:eqversion: -

Trust: 0.2

sources: IVD: b40e48ff-a5af-4308-9fd6-615f0a36d9ae // CNVD: CNVD-2017-15913 // BID: 99291 // JVNDB: JVNDB-2017-006078 // CNNVD: CNNVD-201704-1051 // NVD: CVE-2017-7919

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-7919
value: CRITICAL

Trust: 1.0

NVD: CVE-2017-7919
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2017-15913
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201704-1051
value: CRITICAL

Trust: 0.6

IVD: b40e48ff-a5af-4308-9fd6-615f0a36d9ae
value: CRITICAL

Trust: 0.2

VULHUB: VHN-116122
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-7919
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-15913
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: b40e48ff-a5af-4308-9fd6-615f0a36d9ae
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-116122
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-7919
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: IVD: b40e48ff-a5af-4308-9fd6-615f0a36d9ae // CNVD: CNVD-2017-15913 // VULHUB: VHN-116122 // JVNDB: JVNDB-2017-006078 // CNNVD: CNNVD-201704-1051 // NVD: CVE-2017-7919

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.9

sources: VULHUB: VHN-116122 // JVNDB: JVNDB-2017-006078 // NVD: CVE-2017-7919

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201704-1051

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201704-1051

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-006078

PATCH

title:Top Pageurl:https://www.newport.com/

Trust: 0.8

title:A variety of Newport product certifications to bypass the patchurl:https://www.cnvd.org.cn/patchInfo/show/98537

Trust: 0.6

sources: CNVD: CNVD-2017-15913 // JVNDB: JVNDB-2017-006078

EXTERNAL IDS

db:NVDid:CVE-2017-7919

Trust: 3.6

db:ICS CERTid:ICSA-17-178-01

Trust: 3.4

db:BIDid:99291

Trust: 2.6

db:CNNVDid:CNNVD-201704-1051

Trust: 0.9

db:CNVDid:CNVD-2017-15913

Trust: 0.8

db:JVNDBid:JVNDB-2017-006078

Trust: 0.8

db:IVDid:B40E48FF-A5AF-4308-9FD6-615F0A36D9AE

Trust: 0.2

db:VULHUBid:VHN-116122

Trust: 0.1

sources: IVD: b40e48ff-a5af-4308-9fd6-615f0a36d9ae // CNVD: CNVD-2017-15913 // VULHUB: VHN-116122 // BID: 99291 // JVNDB: JVNDB-2017-006078 // CNNVD: CNNVD-201704-1051 // NVD: CVE-2017-7919

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-17-178-01

Trust: 3.4

url:http://www.securityfocus.com/bid/99291

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-7919

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-7919

Trust: 0.8

url:https://www.newport.com/

Trust: 0.3

sources: CNVD: CNVD-2017-15913 // VULHUB: VHN-116122 // BID: 99291 // JVNDB: JVNDB-2017-006078 // CNNVD: CNNVD-201704-1051 // NVD: CVE-2017-7919

CREDITS

Maxim Rupp.

Trust: 0.3

sources: BID: 99291

SOURCES

db:IVDid:b40e48ff-a5af-4308-9fd6-615f0a36d9ae
db:CNVDid:CNVD-2017-15913
db:VULHUBid:VHN-116122
db:BIDid:99291
db:JVNDBid:JVNDB-2017-006078
db:CNNVDid:CNNVD-201704-1051
db:NVDid:CVE-2017-7919

LAST UPDATE DATE

2025-04-20T23:26:02.866000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-15913date:2017-07-21T00:00:00
db:VULHUBid:VHN-116122date:2019-10-09T00:00:00
db:BIDid:99291date:2017-06-27T00:00:00
db:JVNDBid:JVNDB-2017-006078date:2017-08-17T00:00:00
db:CNNVDid:CNNVD-201704-1051date:2019-10-17T00:00:00
db:NVDid:CVE-2017-7919date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:IVDid:b40e48ff-a5af-4308-9fd6-615f0a36d9aedate:2017-07-21T00:00:00
db:CNVDid:CNVD-2017-15913date:2017-07-21T00:00:00
db:VULHUBid:VHN-116122date:2017-07-03T00:00:00
db:BIDid:99291date:2017-06-27T00:00:00
db:JVNDBid:JVNDB-2017-006078date:2017-08-17T00:00:00
db:CNNVDid:CNNVD-201704-1051date:2017-04-21T00:00:00
db:NVDid:CVE-2017-7919date:2017-07-03T19:29:00.207