Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-12717

EPSS 0.39% · P60
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-12717

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A maliciously crafted dll file placed earlier in the search path may allow an attacker to execute code within the context of the application.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
对搜索路径元素未加控制
Source: NVD (National Vulnerability Database)
Vulnerability Title
Advantech WebAccess 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Advantech WebAccess是研华(Advantech)公司的一套基于浏览器架构的HMI/SCADA软件。该软件支持动态图形显示和实时数据控制,并提供远程控制和管理自动化设备的功能。 Advantech WebAccess 8.2_20170817之前的版本中存在安全漏洞。攻击者可借助被提前放置在搜索路径中恶意构建的dll文件利用该漏洞在应用程序的上下文中执行代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-Advantech WebAccess Advantech WebAccess -

II. Public POCs for CVE-2017-12717

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-12717

Please Login to view more intelligence information

Same Patch Batch · n/a · 2017-08-30 · 39 CVEs total

CVE-2017-13768ImageMagick 代码问题漏洞
CVE-2017-13780EyesOfNetwork web interface 路径遍历漏洞
CVE-2016-10504OpenJPEG 缓冲区错误漏洞
CVE-2016-10505OpenJPEG 代码问题漏洞
CVE-2016-10506OpenJPEG 数字错误漏洞
CVE-2016-10507OpenJPEG 数字错误漏洞
CVE-2017-13764Wireshark Modbu解析器安全漏洞
CVE-2017-13765Wireshark IrCOMM解析器缓冲区错误漏洞
CVE-2017-13766Wireshark Profinet I/O解析器安全漏洞
CVE-2017-13767Wireshark MSDP解析器资源管理错误漏洞
CVE-2017-12713Advantech WebAccess 安全漏洞
CVE-2017-13769ImageMagick 安全漏洞
CVE-2017-13774Hikvision iVMS-4200 安全漏洞
CVE-2017-13775GraphicsMagick 安全漏洞
CVE-2017-13776GraphicsMagick 安全漏洞
CVE-2017-13777GraphicsMagick 安全漏洞
CVE-2017-13778Fiyo CMS 跨站脚本漏洞
CVE-2017-13762ONOS 跨站脚本漏洞
CVE-2017-13763ONOS 资源管理错误漏洞
CVE-2017-12069多款Siemens产品OPC Foundation UA .NET Sample Code和Local Discovery Server 安全漏洞

Showing top 20 of 39 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-12717

No comments yet


Leave a comment