Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-5156

EPSS 0.13% · P33
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-5156

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Schneider Electric Wonderware InTouch Access Anywhere 跨站请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Schneider Electric Wonderware InTouch是法国施耐德电气(Schneider Electric)公司的一套开放的、可扩展的HMI和SCADA监控解决方案,它可创建标准化的、可重复使用的可视化应用程序。Schneider Electric Wonderware InTouch Access Anywhere Server是一款可通过Web浏览器访问InTouch应用程序的产品。 Schneider Electric Wonderware InTouch Access Any
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-Schneider Electric Wonderware InTouch Access Anywhere Schneider Electric Wonderware InTouch Access Anywhere -

II. Public POCs for CVE-2017-5156

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-5156

Please Login to view more intelligence information

Same Patch Batch · n/a · 2017-04-20 · 93 CVEs total

CVE-2016-7538ImageMagick 缓冲区错误漏洞
CVE-2016-7534ImageMagick 安全漏洞
CVE-2016-7530ImageMagick 安全漏洞
CVE-2016-7525ImageMagick 缓冲区错误漏洞
CVE-2016-7521ImageMagick 缓冲区错误漏洞
CVE-2016-7520ImageMagick 缓冲区错误漏洞
CVE-2016-7518ImageMagick 安全漏洞
CVE-2016-7517ImageMagick 缓冲区错误漏洞
CVE-2016-7526ImageMagick 缓冲区错误漏洞
CVE-2016-7536ImageMagick 输入验证错误漏洞
CVE-2016-7535ImageMagick 安全漏洞
CVE-2016-7540ImageMagick 安全漏洞
CVE-2017-5183NetIQ Access Manager 跨站脚本漏洞
CVE-2017-5158Schneider Electric Wonderware InTouch Access Anywhere 信息泄露漏洞
CVE-2017-5160Schneider Electric Wonderware InTouch Access Anywhere 安全漏洞
CVE-2015-8285QuickHeal webssx.sys驱动程序缓冲区错误漏洞
CVE-2016-1161ZOHO ManageEngine Password Manager Pro 跨站请求伪造漏洞
CVE-2016-3729Moodle 安全漏洞
CVE-2016-3731Moodle 安全漏洞
CVE-2016-3732Moodle 安全漏洞

Showing top 20 of 93 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-5156

No comments yet


Leave a comment