CVE-2017-7916
Last modified
CVE-2017-7916 is a vulnerability of currently unknown severity. A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. A malicious user may be able to gain access to configuration information that should be restricted.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Abb | Vsn300 Firmware | <= 1.8.15 |
| Abb | Vsn300 For React Firmware | 2.1.3 |
References
- http://www.securityfocus.com/bid/99558Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-192-03Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/99558Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-192-03Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7916?
How severe is CVE-2017-7916?
How do I fix CVE-2017-7916?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7910A Stack-Based Buffer Overflow issue was discovered in Digita…
- CVE-2017-7911A Code Injection issue was discovered in CyberVision Kaa IoT…
- CVE-2017-7912Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to…
- CVE-2017-7913A Plaintext Storage of a Password issue was discovered in Mo…
- CVE-2017-7914A Missing Authorization issue was discovered in Rockwell Aut…
- CVE-2017-7915An Improper Restriction of Excessive Authentication Attempts…
- CVE-2017-7917A Cross-Site Request Forgery issue was discovered in Moxa On…
- CVE-2017-7918An Improper Access Control issue was discovered in Cambium N…
- CVE-2017-7919An Improper Authentication issue was discovered in Newport X…
- CVE-2017-7920An Improper Authentication issue was discovered in ABB VSN30…
- CVE-2017-7921An Improper Authentication issue was discovered in Hikvision…9.8
- CVE-2017-7922An Improper Privilege Management issue was discovered in Cam…
Are you affected by CVE-2017-7916?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
