{"api_version":"1","generated_at":"2026-07-23T03:46:32+00:00","cve":"CVE-2017-5161","urls":{"html":"https://cve.report/CVE-2017-5161","api":"https://cve.report/api/cve/CVE-2017-5161.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-5161","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-5161"},"summary":{"title":"CVE-2017-5161","description":"An issue was discovered in Sielco Sistemi Winlog Lite SCADA Software, versions prior to Version 3.02.01, and Winlog Pro SCADA Software, versions prior to Version 3.02.01. An uncontrolled search path element (DLL Hijacking) vulnerability has been identified. Exploitation of this vulnerability could give an attacker access to the system with the same level of privilege as the application that utilizes the malicious DLL.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2017-02-13 21:59:00","updated_at":"2017-03-15 17:44:00"},"problem_types":["CWE-427"],"metrics":[],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-038-01","name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-038-01","refsource":"MISC","tags":["Mitigation","Third Party Advisory","US Government Resource"],"title":"Sielco Sistemi Winlog SCADA Software | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/96119","name":"96119","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Sielco Sistemi Winlog Pro/ Winlog Lite CVE-2017-5161 DLL Loading Local Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-5161","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5161","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"5161","vulnerable":"1","versionEndIncluding":"3.01.10","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sielcosistemi","cpe5":"winlog_lite","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5161","vulnerable":"1","versionEndIncluding":"3.01.10","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sielcosistemi","cpe5":"winlog_pro","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-5161","qid":"590964","title":"Sielco Sistemi Winlog SCADA Software Uncontrolled Search Path Element Vulnerability (ICSA-17-038-01)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-5161","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Sielco Sistemi Winlog SCADA Software prior to Version 3.02.01","version":{"version_data":[{"version_value":"Sielco Sistemi Winlog SCADA Software prior to Version 3.02.01"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Sielco Sistemi Winlog Lite SCADA Software, versions prior to Version 3.02.01, and Winlog Pro SCADA Software, versions prior to Version 3.02.01. An uncontrolled search path element (DLL Hijacking) vulnerability has been identified. Exploitation of this vulnerability could give an attacker access to the system with the same level of privilege as the application that utilizes the malicious DLL."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Sielco Sistemi Winlog SCADA Software DLL Hijacking"}]}]},"references":{"reference_data":[{"name":"96119","refsource":"BID","url":"http://www.securityfocus.com/bid/96119"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-038-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-038-01"}]}},"nvd":{"publishedDate":"2017-02-13 21:59:00","lastModifiedDate":"2017-03-15 17:44:00","problem_types":["CWE-427"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"},"exploitabilityScore":0.6,"impactScore":6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9.3},"severity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sielcosistemi:winlog_lite:*:*:*:*:*:*:*:*","versionEndIncluding":"3.01.10","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sielcosistemi:winlog_pro:*:*:*:*:*:*:*:*","versionEndIncluding":"3.01.10","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"5161","Ordinal":"101661","Title":"CVE-2017-5161","CVE":"CVE-2017-5161","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"5161","Ordinal":"1","NoteData":"An issue was discovered in Sielco Sistemi Winlog Lite SCADA Software, versions prior to Version 3.02.01, and Winlog Pro SCADA Software, versions prior to Version 3.02.01. An uncontrolled search path element (DLL Hijacking) vulnerability has been identified. Exploitation of this vulnerability could give an attacker access to the system with the same level of privilege as the application that utilizes the malicious DLL.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"5161","Ordinal":"2","NoteData":"2017-02-13","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"5161","Ordinal":"3","NoteData":"2017-02-14","Type":"Other","Title":"Modified"}]}}}