ID

VAR-201709-1100


CVE

CVE-2017-7972


TITLE

Schneider Electric's PowerSCADA Anywhere and Citect Anywhere Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2017-008375

DESCRIPTION

A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to escape out of remote PowerSCADA Anywhere applications and launch other processes. Schneider Electric's PowerSCADA Anywhere and Citect Anywhere Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. PowerSCADA Anywhere is SCADA and power monitoring software. Citect is an industrial automation operation and monitoring software. PowerSCADA Anywhere 1.0 and Citect Anywhere version 1.0 have bugs in the implementation of command delimiters. Attackers with close network locations can escape remote applications and start other processes. Schneider Electric PowerSCADA Anywhere and Citect Anywhere are prone to the following security vulnerabilities: 1. A cross-site request-forgery vulnerability 2. An information-disclosure vulnerability 3. Multiple security-bypass vulnerabilities Exploiting these issues could allow an attacker to obtain sensitive information, bypass certain security restrictions, perform unauthorized actions, or gain access to the affected system. Following products and versions are vulnerable: PowerSCADA Anywhere 1.0 redistributed with PowerSCADA Expert 8.1 and PowerSCADA Expert 8.2 Citect Anywhere 1.0

Trust: 2.61

sources: NVD: CVE-2017-7972 // JVNDB: JVNDB-2017-008375 // CNVD: CNVD-2017-22846 // BID: 99913 // IVD: 35ce550a-d7da-4ffc-8c4c-9ff79a6f5f23

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 35ce550a-d7da-4ffc-8c4c-9ff79a6f5f23 // CNVD: CNVD-2017-22846

AFFECTED PRODUCTS

vendor:schneider electricmodel:powerscada anywherescope:eqversion:1.0

Trust: 2.7

vendor:schneider electricmodel:citect anywherescope:eqversion:1.0

Trust: 2.7

vendor:schneidermodel:electric citect anywherescope:eqversion:1.0

Trust: 0.6

vendor:schneidermodel:electric powerscada anywherescope:eqversion:1.0

Trust: 0.6

vendor:schneider electricmodel:powerscada expertscope:eqversion:8.2

Trust: 0.3

vendor:schneider electricmodel:powerscada expertscope:eqversion:8.1

Trust: 0.3

vendor:powerscada anywheremodel: - scope:eqversion:1.0

Trust: 0.2

vendor:citect anywheremodel: - scope:eqversion:1.0

Trust: 0.2

sources: IVD: 35ce550a-d7da-4ffc-8c4c-9ff79a6f5f23 // CNVD: CNVD-2017-22846 // BID: 99913 // JVNDB: JVNDB-2017-008375 // CNNVD: CNNVD-201704-896 // NVD: CVE-2017-7972

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-7972
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-7972
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2017-22846
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201704-896
value: MEDIUM

Trust: 0.6

IVD: 35ce550a-d7da-4ffc-8c4c-9ff79a6f5f23
value: MEDIUM

Trust: 0.2

nvd@nist.gov: CVE-2017-7972
severity: MEDIUM
baseScore: 5.2
vectorString: AV:A/AC:L/AU:S/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 5.1
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-22846
severity: MEDIUM
baseScore: 5.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 6.5
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 35ce550a-d7da-4ffc-8c4c-9ff79a6f5f23
severity: MEDIUM
baseScore: 5.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 6.5
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

nvd@nist.gov: CVE-2017-7972
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 2.1
impactScore: 3.4
version: 3.0

Trust: 1.8

sources: IVD: 35ce550a-d7da-4ffc-8c4c-9ff79a6f5f23 // CNVD: CNVD-2017-22846 // JVNDB: JVNDB-2017-008375 // CNNVD: CNNVD-201704-896 // NVD: CVE-2017-7972

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-264

Trust: 0.8

sources: JVNDB: JVNDB-2017-008375 // NVD: CVE-2017-7972

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-201704-896

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201704-896

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-008375

PATCH

title:SEVD-2017-173-01url:https://www.schneider-electric.com/en/download/document/SEVD-2017-173-01/

Trust: 0.8

title:Security Notification - Citect Anywhereurl:https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9071-security-notification-citect-anywhere

Trust: 0.8

title:Schneider Electric PowerSCADA Anywhere/Citect Anywhere Command Delimiter Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/100827

Trust: 0.6

title:Schneider Electric PowerSCADA Anywhere and Citect Anywhere Fixes for permission permissions and access control vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=99736

Trust: 0.6

sources: CNVD: CNVD-2017-22846 // JVNDB: JVNDB-2017-008375 // CNNVD: CNNVD-201704-896

EXTERNAL IDS

db:NVDid:CVE-2017-7972

Trust: 3.5

db:SCHNEIDERid:SEVD-2017-173-01

Trust: 1.9

db:BIDid:99913

Trust: 1.9

db:ICS CERTid:ICSA-17-201-01

Trust: 0.9

db:CNVDid:CNVD-2017-22846

Trust: 0.8

db:CNNVDid:CNNVD-201704-896

Trust: 0.8

db:JVNDBid:JVNDB-2017-008375

Trust: 0.8

db:IVDid:35CE550A-D7DA-4FFC-8C4C-9FF79A6F5F23

Trust: 0.2

sources: IVD: 35ce550a-d7da-4ffc-8c4c-9ff79a6f5f23 // CNVD: CNVD-2017-22846 // BID: 99913 // JVNDB: JVNDB-2017-008375 // CNNVD: CNNVD-201704-896 // NVD: CVE-2017-7972

REFERENCES

url:http://www.schneider-electric.com/en/download/document/sevd-2017-173-01/

Trust: 1.9

url:https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9071-security-notification-citect-anywhere

Trust: 1.6

url:http://www.securityfocus.com/bid/99913

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2017-7972

Trust: 1.4

url:https://ics-cert.us-cert.gov/advisories/icsa-17-201-01

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-7972

Trust: 0.8

url:http://www.schneider-electric.com/site/home/index.cfm/ww/?selectcountry=true

Trust: 0.3

sources: CNVD: CNVD-2017-22846 // BID: 99913 // JVNDB: JVNDB-2017-008375 // CNNVD: CNNVD-201704-896 // NVD: CVE-2017-7972

CREDITS

Schneider Electric

Trust: 0.3

sources: BID: 99913

SOURCES

db:IVDid:35ce550a-d7da-4ffc-8c4c-9ff79a6f5f23
db:CNVDid:CNVD-2017-22846
db:BIDid:99913
db:JVNDBid:JVNDB-2017-008375
db:CNNVDid:CNNVD-201704-896
db:NVDid:CVE-2017-7972

LAST UPDATE DATE

2025-04-20T23:22:11.179000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-22846date:2017-08-25T00:00:00
db:BIDid:99913date:2017-07-20T00:00:00
db:JVNDBid:JVNDB-2017-008375date:2017-10-17T00:00:00
db:CNNVDid:CNNVD-201704-896date:2019-10-23T00:00:00
db:NVDid:CVE-2017-7972date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:IVDid:35ce550a-d7da-4ffc-8c4c-9ff79a6f5f23date:2017-08-25T00:00:00
db:CNVDid:CNVD-2017-22846date:2017-08-25T00:00:00
db:BIDid:99913date:2017-07-20T00:00:00
db:JVNDBid:JVNDB-2017-008375date:2017-10-17T00:00:00
db:CNNVDid:CNNVD-201704-896date:2017-04-20T00:00:00
db:NVDid:CVE-2017-7972date:2017-09-26T01:29:03.617