First published: Mon Aug 07 2017(Updated: )
A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. A malicious user may be able to gain access to configuration information that should be restricted.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
ABB VSN300 for React | <=1.8.15 | |
ABB VSN300 for React | ||
ABB VSN300 for React | =2.1.3 | |
ABB VSN300 for React |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7916 has a moderate severity rating due to improper privilege restrictions on the Guest account.
To mitigate CVE-2017-7916, upgrade to ABB VSN300 WiFi Logger Card firmware version 1.8.16 or later, or VSN300 WiFi Logger Card for React version 2.1.4 or later.
CVE-2017-7916 affects ABB VSN300 WiFi Logger Card firmware versions 1.8.15 and earlier, and VSN300 WiFi Logger Card for React versions 2.1.3 and earlier.
CVE-2017-7916 is classified as a Permissions, Privileges, and Access Controls issue.
Yes, a malicious user may exploit CVE-2017-7916 to gain unauthorized access via the Guest account.