{"api_version":"1","generated_at":"2026-07-23T02:16:33+00:00","cve":"CVE-2017-7909","urls":{"html":"https://cve.report/CVE-2017-7909","api":"https://cve.report/api/cve/CVE-2017-7909.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-7909","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-7909"},"summary":{"title":"CVE-2017-7909","description":"A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client authentication and redirect unauthorized users. Attackers may intercept requests and bypass authentication to access restricted web pages.","state":"PUBLISHED","assigner":"icscert","published_at":"2017-05-06 00:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-603","CWE-287","CWE-603 CWE-603"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/98257","name":"http://www.securityfocus.com/bid/98257","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Advantech B+B SmartWorx MESR901 CVE-2017-7909 Authentication Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-122-03","name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-122-03","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Advantech B+B SmartWorx MESR901 | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-7909","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7909","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Advantech B+B SmartWorx MESR901","version":"affected Advantech B+B SmartWorx MESR901","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"7909","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"advantech_b\\+b_smartworx","cpe5":"mesr901","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"7909","vulnerable":"1","versionEndIncluding":"1.5.2","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"advantech_b\\+b_smartworx","cpe5":"mesr901_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T16:19:29.487Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-122-03"},{"name":"98257","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/98257"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Advantech B+B SmartWorx MESR901","vendor":"n/a","versions":[{"status":"affected","version":"Advantech B+B SmartWorx MESR901"}]}],"datePublic":"2017-05-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client authentication and redirect unauthorized users. Attackers may intercept requests and bypass authentication to access restricted web pages."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-603","description":"CWE-603","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-05-08T09:57:01.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"tags":["x_refsource_MISC"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-122-03"},{"name":"98257","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/98257"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-7909","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Advantech B+B SmartWorx MESR901","version":{"version_data":[{"version_value":"Advantech B+B SmartWorx MESR901"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client authentication and redirect unauthorized users. Attackers may intercept requests and bypass authentication to access restricted web pages."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-603"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-122-03","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-122-03"},{"name":"98257","refsource":"BID","url":"http://www.securityfocus.com/bid/98257"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2017-7909","datePublished":"2017-05-06T00:00:00.000Z","dateReserved":"2017-04-18T00:00:00.000Z","dateUpdated":"2024-08-05T16:19:29.487Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-05-06 00:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-603","CWE-287","CWE-603 CWE-603"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:advantech_b\\+b_smartworx:mesr901_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.5.2","matchCriteriaId":"6AB9FB4D-4FDB-40AB-A58C-6AD9DAACC686"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:advantech_b\\+b_smartworx:mesr901:-:*:*:*:*:*:*:*","matchCriteriaId":"FC538C97-26F5-4DCE-BB28-20F1FD470FED"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"7909","Ordinal":"1","Title":"CVE-2017-7909","CVE":"CVE-2017-7909","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"7909","Ordinal":"1","NoteData":"A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client authentication and redirect unauthorized users. Attackers may intercept requests and bypass authentication to access restricted web pages.","Type":"Description","Title":"CVE-2017-7909"},{"CveYear":"2017","CveId":"7909","Ordinal":"2","NoteData":"2017-05-05","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"7909","Ordinal":"3","NoteData":"2017-05-08","Type":"Other","Title":"Modified"}]}}}