CVE-2017-7907
Summary
| CVE | CVE-2017-7907 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-19 03:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity reference, or XXE) may allow an attacker to enter malicious input through the application which could cause a denial of service or disclose file contents from a server or connected network. |
Risk And Classification
Primary CVSS: v3.0 6.6 MEDIUM from [email protected]
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
Problem Types: CWE-611 | CWE-611 CWE-611
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 6.6 | MEDIUM | CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H |
| 2.0 | [email protected] | Primary | 3.3 | AV:L/AC:M/Au:N/C:P/I:N/A:P |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
HighCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
PartialAV:L/AC:M/Au:N/C:P/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Schneider-electric | Wonderware Historian Client | All | sp1 | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Schneider Electric Wonderware Historian Client | affected Schneider Electric Wonderware Historian Client | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Wonderware Historian Client CVE-2017-7907 Local XML External Entity Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Wonderware Historian Client XML External Entity Processing Flaw Lets Remote Users Deny Service and Potentially Read Files on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| AVEVA - Global Leader in Industrial Software | af854a3a-2127-422b-91ae-364da2661108 | software.schneider-electric.com | Vendor Advisory |
| Schneider Electric Wonderware Historian Client | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Mitigation, Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.