ID

VAR-201711-0413


CVE

CVE-2017-14025


TITLE

ABB FOX515T Information Disclosure Vulnerability

Trust: 0.8

sources: IVD: 094d9c9b-ca7a-44fd-9d10-0883f57157aa // CNVD: CNVD-2017-32177

DESCRIPTION

An Improper Input Validation issue was discovered in ABB FOX515T release 1.0. An improper input validation vulnerability has been identified, allowing a local attacker to provide a malicious parameter to the script that is not validated by the application, This could enable the attacker to retrieve any file on the server. FOX515 is a universal communication platform based on TDM technology (time division multiplexing). ABB FOX515T is prone to a local information-disclosure vulnerability. Successful exploits may allow an attacker to obtain sensitive information that may lead to further attacks. ABB FOX515T 1.0 is vulnerable; other versions may also be affected. ABB FOX515T is a multi-functional optical transmission equipment produced by Swiss ABB company

Trust: 2.7

sources: NVD: CVE-2017-14025 // JVNDB: JVNDB-2017-009949 // CNVD: CNVD-2017-32177 // BID: 101662 // IVD: 094d9c9b-ca7a-44fd-9d10-0883f57157aa // VULHUB: VHN-104706

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 094d9c9b-ca7a-44fd-9d10-0883f57157aa // CNVD: CNVD-2017-32177

AFFECTED PRODUCTS

vendor:abbmodel:fox515tscope:eqversion:1.0

Trust: 2.3

vendor:hitachienergymodel:fox515tscope:eqversion:1.0

Trust: 1.0

vendor:fox515tmodel: - scope:eqversion:1.0

Trust: 0.2

sources: IVD: 094d9c9b-ca7a-44fd-9d10-0883f57157aa // CNVD: CNVD-2017-32177 // BID: 101662 // JVNDB: JVNDB-2017-009949 // CNNVD: CNNVD-201708-1250 // NVD: CVE-2017-14025

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-14025
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-14025
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2017-32177
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201708-1250
value: MEDIUM

Trust: 0.6

IVD: 094d9c9b-ca7a-44fd-9d10-0883f57157aa
value: MEDIUM

Trust: 0.2

VULHUB: VHN-104706
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2017-14025
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-32177
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 094d9c9b-ca7a-44fd-9d10-0883f57157aa
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-104706
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-14025
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: IVD: 094d9c9b-ca7a-44fd-9d10-0883f57157aa // CNVD: CNVD-2017-32177 // VULHUB: VHN-104706 // JVNDB: JVNDB-2017-009949 // CNNVD: CNNVD-201708-1250 // NVD: CVE-2017-14025

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-104706 // JVNDB: JVNDB-2017-009949 // NVD: CVE-2017-14025

THREAT TYPE

local

Trust: 0.9

sources: BID: 101662 // CNNVD: CNNVD-201708-1250

TYPE

Input validation error

Trust: 1.1

sources: IVD: 094d9c9b-ca7a-44fd-9d10-0883f57157aa // BID: 101662 // CNNVD: CNNVD-201708-1250

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-009949

PATCH

title:Top Pageurl:http://new.abb.com/

Trust: 0.8

sources: JVNDB: JVNDB-2017-009949

EXTERNAL IDS

db:NVDid:CVE-2017-14025

Trust: 3.6

db:ICS CERTid:ICSA-17-304-01

Trust: 3.4

db:BIDid:101662

Trust: 2.0

db:CNNVDid:CNNVD-201708-1250

Trust: 0.9

db:CNVDid:CNVD-2017-32177

Trust: 0.8

db:JVNDBid:JVNDB-2017-009949

Trust: 0.8

db:IVDid:094D9C9B-CA7A-44FD-9D10-0883F57157AA

Trust: 0.2

db:VULHUBid:VHN-104706

Trust: 0.1

sources: IVD: 094d9c9b-ca7a-44fd-9d10-0883f57157aa // CNVD: CNVD-2017-32177 // VULHUB: VHN-104706 // BID: 101662 // JVNDB: JVNDB-2017-009949 // CNNVD: CNNVD-201708-1250 // NVD: CVE-2017-14025

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-17-304-01

Trust: 3.4

url:http://www.securityfocus.com/bid/101662

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-14025

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-14025

Trust: 0.8

url:http://www.abb.com/

Trust: 0.3

sources: CNVD: CNVD-2017-32177 // VULHUB: VHN-104706 // BID: 101662 // JVNDB: JVNDB-2017-009949 // CNNVD: CNNVD-201708-1250 // NVD: CVE-2017-14025

CREDITS

Ketan Bali

Trust: 0.3

sources: BID: 101662

SOURCES

db:IVDid:094d9c9b-ca7a-44fd-9d10-0883f57157aa
db:CNVDid:CNVD-2017-32177
db:VULHUBid:VHN-104706
db:BIDid:101662
db:JVNDBid:JVNDB-2017-009949
db:CNNVDid:CNNVD-201708-1250
db:NVDid:CVE-2017-14025

LAST UPDATE DATE

2025-04-20T23:03:58.074000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-32177date:2017-11-01T00:00:00
db:VULHUBid:VHN-104706date:2019-10-09T00:00:00
db:BIDid:101662date:2017-12-19T22:00:00
db:JVNDBid:JVNDB-2017-009949date:2017-11-29T00:00:00
db:CNNVDid:CNNVD-201708-1250date:2019-10-17T00:00:00
db:NVDid:CVE-2017-14025date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:IVDid:094d9c9b-ca7a-44fd-9d10-0883f57157aadate:2017-11-01T00:00:00
db:CNVDid:CNVD-2017-32177date:2017-11-01T00:00:00
db:VULHUBid:VHN-104706date:2017-11-06T00:00:00
db:BIDid:101662date:2017-10-31T00:00:00
db:JVNDBid:JVNDB-2017-009949date:2017-11-29T00:00:00
db:CNNVDid:CNNVD-201708-1250date:2017-08-31T00:00:00
db:NVDid:CVE-2017-14025date:2017-11-06T22:29:00.303