CVE-2017-6041
Summary
| CVE | CVE-2017-6041 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-30 03:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C; M3210 terminal associated with the same systems as the M3000 terminal identified above; M3000 desktop software associated with the same systems as the M3000 terminal identified above; MAC4 controller associated with the same systems as the M3000 terminal identified above; SensorX23 X-ray machine; SensorX25 X-ray machine; and MWS2 weighing system. This vulnerability allows an attacker to modify the operation and upload firmware changes without detection. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-434 | CWE-434 CWE-434
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Marel | A320 | - | All | All | All |
| Operating System | Marel | A320 Firmware | - | All | All | All |
| Hardware | Marel | A325 | - | All | All | All |
| Operating System | Marel | A325 Firmware | - | All | All | All |
| Hardware | Marel | A371 | - | All | All | All |
| Operating System | Marel | A371 Firmware | - | All | All | All |
| Hardware | Marel | A520 Master | - | All | All | All |
| Operating System | Marel | A520 Master Firmware | - | All | All | All |
| Hardware | Marel | A520 Slave | - | All | All | All |
| Operating System | Marel | A520 Slave Firmware | - | All | All | All |
| Hardware | Marel | A530 | - | All | All | All |
| Operating System | Marel | A530 Firmware | - | All | All | All |
| Hardware | Marel | A542 | - | All | All | All |
| Operating System | Marel | A542 Firmware | - | All | All | All |
| Hardware | Marel | A571 | - | All | All | All |
| Operating System | Marel | A571 Firmware | - | All | All | All |
| Hardware | Marel | Check Bin Grader | - | All | All | All |
| Operating System | Marel | Check Bin Grader Firmware | - | All | All | All |
| Hardware | Marel | Flowlineqc T376 | - | All | All | All |
| Operating System | Marel | Flowlineqc T376 Firmware | - | All | All | All |
| Hardware | Marel | Ipm3 Dual Cam | - | All | All | All |
| Operating System | Marel | Ipm3 Dual Cam Firmware | 132 | All | All | All |
| Operating System | Marel | Ipm3 Dual Cam Firmware | 139 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Marel Food Processing Systems | affected Marel Food Processing Systems | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Marel Food Processing Systems | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Mitigation, Third Party Advisory, US Government Resource |
| Marel Food Processing Systems Security Bypass and Arbitrary File Upload Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.