ID

VAR-201712-0369


CVE

CVE-2017-14855


TITLE

Red Lion HMI Panel error handling vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-011951

DESCRIPTION

Red Lion HMI panels allow remote attackers to cause a denial of service (software exception) via an HTTP POST request to a long URI that does not exist, as demonstrated by version HMI 2.41 PLC 2.42. Red Lion HMI The panel contains an error handling vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Red Lion HMI panels HMI is the United States Red Lion Controls One of the company's human-machine interface products for industrial control. PLC It is a programmable logic controller. Red Lion HMI panels HMI 2.41 in version PLC 2.42 version has a security vulnerability

Trust: 1.71

sources: NVD: CVE-2017-14855 // JVNDB: JVNDB-2017-011951 // VULHUB: VHN-105619

AFFECTED PRODUCTS

vendor:redlionmodel:hmi panelscope:eqversion:2.41

Trust: 1.6

vendor:red lion controlsmodel:hmi panelscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2017-011951 // CNNVD: CNNVD-201709-1187 // NVD: CVE-2017-14855

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-14855
value: HIGH

Trust: 1.0

NVD: CVE-2017-14855
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201709-1187
value: HIGH

Trust: 0.6

VULHUB: VHN-105619
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-14855
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-105619
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-14855
baseSeverity: HIGH
baseScore: 8.6
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 4.0
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-105619 // JVNDB: JVNDB-2017-011951 // CNNVD: CNNVD-201709-1187 // NVD: CVE-2017-14855

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-388

Trust: 0.9

sources: VULHUB: VHN-105619 // JVNDB: JVNDB-2017-011951 // NVD: CVE-2017-14855

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201709-1187

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201709-1187

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-011951

PATCH

title:Top Pageurl:http://www.redlion.net/

Trust: 0.8

sources: JVNDB: JVNDB-2017-011951

EXTERNAL IDS

db:NVDid:CVE-2017-14855

Trust: 2.5

db:JVNDBid:JVNDB-2017-011951

Trust: 0.8

db:CNNVDid:CNNVD-201709-1187

Trust: 0.7

db:VULHUBid:VHN-105619

Trust: 0.1

sources: VULHUB: VHN-105619 // JVNDB: JVNDB-2017-011951 // CNNVD: CNNVD-201709-1187 // NVD: CVE-2017-14855

REFERENCES

url:http://misteralfa-hack.blogspot.cl/2017/12/red-lion-guru-mode-cve-2017-14855.html

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-14855

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-14855

Trust: 0.8

url:http://misteralfa-hack.blogspot.jp/2017/12/red-lion-guru-mode-cve-2017-14855.html

Trust: 0.8

sources: VULHUB: VHN-105619 // JVNDB: JVNDB-2017-011951 // CNNVD: CNNVD-201709-1187 // NVD: CVE-2017-14855

SOURCES

db:VULHUBid:VHN-105619
db:JVNDBid:JVNDB-2017-011951
db:CNNVDid:CNNVD-201709-1187
db:NVDid:CVE-2017-14855

LAST UPDATE DATE

2025-04-20T23:30:49.634000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-105619date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2017-011951date:2018-02-08T00:00:00
db:CNNVDid:CNNVD-201709-1187date:2019-10-23T00:00:00
db:NVDid:CVE-2017-14855date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-105619date:2017-12-30T00:00:00
db:JVNDBid:JVNDB-2017-011951date:2018-02-08T00:00:00
db:CNNVDid:CNNVD-201709-1187date:2017-09-28T00:00:00
db:NVDid:CVE-2017-14855date:2017-12-30T17:29:00.217