{"api_version":"1","generated_at":"2026-07-23T10:40:17+00:00","cve":"CVE-2017-13993","urls":{"html":"https://cve.report/CVE-2017-13993","api":"https://cve.report/api/cve/CVE-2017-13993.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-13993","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-13993"},"summary":{"title":"CVE-2017-13993","description":"An Uncontrolled Search Path or Element issue was discovered in i-SENS SmartLog Diabetes Management Software, Version 2.4.0 and prior versions. An uncontrolled search path element vulnerability has been identified which could be exploited by placing a specially crafted DLL file in the search path. If the malicious DLL is loaded prior to the valid DLL, an attacker could execute arbitrary code on the system. This vulnerability does not affect the connected blood glucose monitor and would not impact delivery of therapy to the patient.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2017-10-05 01:29:00","updated_at":"2019-10-09 23:23:00"},"problem_types":["CWE-427"],"metrics":[],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSMA-17-250-01","name":"https://ics-cert.us-cert.gov/advisories/ICSMA-17-250-01","refsource":"MISC","tags":["Patch","Third Party Advisory","US Government Resource"],"title":"i-SENS, Inc. SmartLog Diabetes Management Software | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/100659","name":"100659","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"i-SENS SmartLog Diabetes Management Software CVE-2017-13993 Untrusted Search Path vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-13993","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-13993","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"13993","vulnerable":"1","versionEndIncluding":"2.4.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"i-sens","cpe5":"smartlog_diabetes_management_software","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-13993","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"i-SENS, Inc. SmartLog Diabetes Management Software","version":{"version_data":[{"version_value":"i-SENS, Inc. SmartLog Diabetes Management Software"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An Uncontrolled Search Path or Element issue was discovered in i-SENS SmartLog Diabetes Management Software, Version 2.4.0 and prior versions. An uncontrolled search path element vulnerability has been identified which could be exploited by placing a specially crafted DLL file in the search path. If the malicious DLL is loaded prior to the valid DLL, an attacker could execute arbitrary code on the system. This vulnerability does not affect the connected blood glucose monitor and would not impact delivery of therapy to the patient."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-428"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSMA-17-250-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSMA-17-250-01"},{"name":"100659","refsource":"BID","url":"http://www.securityfocus.com/bid/100659"}]}},"nvd":{"publishedDate":"2017-10-05 01:29:00","lastModifiedDate":"2019-10-09 23:23:00","problem_types":["CWE-427"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9.3},"severity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:i-sens:smartlog_diabetes_management_software:*:*:*:*:*:*:*:*","versionEndIncluding":"2.4.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"13993","Ordinal":"111418","Title":"CVE-2017-13993","CVE":"CVE-2017-13993","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"13993","Ordinal":"1","NoteData":"An Uncontrolled Search Path or Element issue was discovered in i-SENS SmartLog Diabetes Management Software, Version 2.4.0 and prior versions. An uncontrolled search path element vulnerability has been identified which could be exploited by placing a specially crafted DLL file in the search path. If the malicious DLL is loaded prior to the valid DLL, an attacker could execute arbitrary code on the system. This vulnerability does not affect the connected blood glucose monitor and would not impact delivery of therapy to the patient.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"13993","Ordinal":"2","NoteData":"2017-10-04","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"13993","Ordinal":"3","NoteData":"2017-10-04","Type":"Other","Title":"Modified"}]}}}