CVE-2017-9631
Summary
| CVE | CVE-2017-9631 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-07-07 17:29:00 UTC |
| Updated | 2023-02-01 17:59:00 UTC |
| Description | A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The null pointer dereference vulnerability could allow an attacker to crash the logger process, causing a denial of service for logging and log-viewing (applications that use the Wonderware ArchestrA Logger continue to run when the Wonderware ArchestrA Logger service is unavailable). |
Risk And Classification
Problem Types: CWE-476
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Schneider-electric | Wonderware Archestra Logger | All | All | All | All |
| Application | Schneider Electric | Wonderware Archestra Logger | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Schneider Wonderware ArchestrA Logger ICSA-17-187-04 Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Wonderware Information Server Flaws in ArchestrA Logger Component RPC Interface Let Remote Users Deny Service and Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Schneider Electric Wonderware ArchestrA Logger | ICS-CERT | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| AVEVA - Global Leader in Industrial Software | MISC | software.schneider-electric.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.