CVE-2017-9967: High severity interactive graphical scada system vulnerability
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-9967?
CVE-2017-9967 is a security misconfiguration vulnerability in Schneider Electric's IGSS SCADA Software.
What versions of Schneider Electric's IGSS SCADA Software are affected by CVE-2017-9967?
Versions 12 and prior of Schneider Electric's IGSS SCADA Software are affected by CVE-2017-9967.
What is the severity rating of CVE-2017-9967?
CVE-2017-9967 has a severity rating of 7.8 (high).
How does CVE-2017-9967 affect the security configuration settings of Schneider Electric's IGSS SCADA Software?
CVE-2017-9967 results in weak security configuration settings, specifically in the improper configuration of Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP).
Is there a security advisory or patch available for CVE-2017-9967?
Yes, a security advisory and patch for CVE-2017-9967 can be found at the following link: [link](https://www.schneider-electric.com/en/download/document/SEVD-2018-037-01/)