CVE-2017-6041

UnknownEPSS 1.85%

Last modified

CVE-2017-6041 is a vulnerability of currently unknown severity. An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C; M3210 terminal associated with the same systems as the M3000 terminal identified above; M3000 desktop software associated with the same systems as the M3000 terminal identified above; MAC4 controller associated with the same systems as the M3000 terminal identified above; SensorX23 X-ray machine; SensorX25 X-ray machine; and MWS2 weighing system. This vulnerability allows an attacker to modify the operation and upload firmware changes without detection.. EPSS estimates a 1.85% chance of exploitation in the next 30 days.

Description

An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C; M3210 terminal associated with the same systems as the M3000 terminal identified above; M3000 desktop software associated with the same systems as the M3000 terminal identified above; MAC4 controller associated with the same systems as the M3000 terminal identified above; SensorX23 X-ray machine; SensorX25 X-ray machine; and MWS2 weighing system. This vulnerability allows an attacker to modify the operation and upload firmware changes without detection.

Metrics

EPSS Probability
1.85%

76.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MarelA320 FirmwareAll versions
MarelA325 FirmwareAll versions
MarelA371 FirmwareAll versions
MarelA520 Master FirmwareAll versions
MarelA520 Slave FirmwareAll versions
MarelA530 FirmwareAll versions
MarelA542 FirmwareAll versions
MarelA571 FirmwareAll versions
MarelCheck Bin Grader FirmwareAll versions
MarelFlowlineqc T376 FirmwareAll versions
MarelIpm3 Dual Cam Firmware132
MarelIpm3 Dual Cam Firmware139
MarelP520 FirmwareAll versions
MarelP574 FirmwareAll versions
MarelSensorx13 Qc Flow Line FirmwareAll versions
MarelSensorx23 Qc Master FirmwareAll versions
MarelSensorx23 Qc Slave FirmwareAll versions
MarelSpeed Batcher FirmwareAll versions
MarelT374 FirmwareAll versions
MarelT377 FirmwareAll versions
MarelV36 FirmwareAll versions
MarelV36b FirmwareAll versions
MarelV36c FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-6041?
An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C; M3210 terminal associated with the same systems as the M3000 terminal identified above; M3000 desktop software associated with the same systems as the M3000 terminal identified above; MAC4 controller associated with the same systems as the M3000 terminal identified above; SensorX23 X-ray machine; SensorX25 X-ray machine; and MWS2 weighing system. This vulnerability allows an attacker to modify the operation and upload firmware changes without detection.
How severe is CVE-2017-6041?
Severity scoring for CVE-2017-6041 is pending analysis. The EPSS model estimates a 1.85% probability of exploitation in the next 30 days.
How do I fix CVE-2017-6041?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-6041?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST