{"api_version":"1","generated_at":"2026-07-23T06:05:58+00:00","cve":"CVE-2017-14019","urls":{"html":"https://cve.report/CVE-2017-14019","api":"https://cve.report/api/cve/CVE-2017-14019.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-14019","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-14019"},"summary":{"title":"CVE-2017-14019","description":"An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted search path or element vulnerability has been identified, which may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate his or her privileges.","state":"PUBLISHED","assigner":"icscert","published_at":"2017-10-19 23:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-428","CWE-428 CWE-428"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.7","severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/101483","name":"http://www.securityfocus.com/bid/101483","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Progea Movicon Multiple Privilege Escalation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-290-01","name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-290-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Progea Movicon SCADA/HMI | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-14019","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14019","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Progea Movicon SCADA/HMI","version":"affected Progea Movicon SCADA/HMI","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"14019","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"progea","cpe5":"movicon","cpe6":"11.5.1181","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T19:13:41.696Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"101483","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/101483"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-290-01"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Progea Movicon SCADA/HMI","vendor":"n/a","versions":[{"status":"affected","version":"Progea Movicon SCADA/HMI"}]}],"datePublic":"2017-10-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted search path or element vulnerability has been identified, which may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate his or her privileges."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-428","description":"CWE-428","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-10-20T09:57:01.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"name":"101483","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/101483"},{"tags":["x_refsource_MISC"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-290-01"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-14019","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Progea Movicon SCADA/HMI","version":{"version_data":[{"version_value":"Progea Movicon SCADA/HMI"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted search path or element vulnerability has been identified, which may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate his or her privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-428"}]}]},"references":{"reference_data":[{"name":"101483","refsource":"BID","url":"http://www.securityfocus.com/bid/101483"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-290-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-290-01"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2017-14019","datePublished":"2017-10-19T23:00:00.000Z","dateReserved":"2017-08-30T00:00:00.000Z","dateUpdated":"2024-08-05T19:13:41.696Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-10-19 23:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-428","CWE-428 CWE-428"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:progea:movicon:11.5.1181:*:*:*:*:*:*:*","matchCriteriaId":"FD23F226-832B-4497-A5BE-68756D6414F4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"14019","Ordinal":"1","Title":"CVE-2017-14019","CVE":"CVE-2017-14019","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"14019","Ordinal":"1","NoteData":"An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted search path or element vulnerability has been identified, which may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate his or her privileges.","Type":"Description","Title":"CVE-2017-14019"},{"CveYear":"2017","CveId":"14019","Ordinal":"2","NoteData":"2017-10-19","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"14019","Ordinal":"3","NoteData":"2017-10-20","Type":"Other","Title":"Modified"}]}}}