CWE
269 264
Advisory Published
Updated

CVE-2017-7916

First published: Mon Aug 07 2017(Updated: )

A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. A malicious user may be able to gain access to configuration information that should be restricted.

Credit: ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
ABB VSN300 for React<=1.8.15
ABB VSN300 for React
ABB VSN300 for React=2.1.3
ABB VSN300 for React

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2017-7916?

    CVE-2017-7916 has a moderate severity rating due to improper privilege restrictions on the Guest account.

  • How do I fix CVE-2017-7916?

    To mitigate CVE-2017-7916, upgrade to ABB VSN300 WiFi Logger Card firmware version 1.8.16 or later, or VSN300 WiFi Logger Card for React version 2.1.4 or later.

  • What products are affected by CVE-2017-7916?

    CVE-2017-7916 affects ABB VSN300 WiFi Logger Card firmware versions 1.8.15 and earlier, and VSN300 WiFi Logger Card for React versions 2.1.3 and earlier.

  • What type of issue is CVE-2017-7916?

    CVE-2017-7916 is classified as a Permissions, Privileges, and Access Controls issue.

  • Can a malicious user exploit CVE-2017-7916?

    Yes, a malicious user may exploit CVE-2017-7916 to gain unauthorized access via the Guest account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203