CVE-2017-13993
Summary
| CVE | CVE-2017-13993 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-05 01:29:00 UTC |
| Updated | 2019-10-09 23:23:00 UTC |
| Description | An Uncontrolled Search Path or Element issue was discovered in i-SENS SmartLog Diabetes Management Software, Version 2.4.0 and prior versions. An uncontrolled search path element vulnerability has been identified which could be exploited by placing a specially crafted DLL file in the search path. If the malicious DLL is loaded prior to the valid DLL, an attacker could execute arbitrary code on the system. This vulnerability does not affect the connected blood glucose monitor and would not impact delivery of therapy to the patient. |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | I-sens | Smartlog Diabetes Management Software | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| i-SENS, Inc. SmartLog Diabetes Management Software | ICS-CERT | MISC | ics-cert.us-cert.gov | Patch, Third Party Advisory, US Government Resource |
| i-SENS SmartLog Diabetes Management Software CVE-2017-13993 Untrusted Search Path vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.