{"api_version":"1","generated_at":"2026-07-23T06:00:14+00:00","cve":"CVE-2017-9625","urls":{"html":"https://cve.report/CVE-2017-9625","api":"https://cve.report/api/cve/CVE-2017-9625.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-9625","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-9625"},"summary":{"title":"CVE-2017-9625","description":"An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settings or execute code remotely.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2017-10-17 22:29:00","updated_at":"2019-10-09 23:30:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-285-03","name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-285-03","refsource":"MISC","tags":["Third Party Advisory","US Government Resource","VDB Entry"],"title":"Envitech Ltd. EnviDAS Ultimate | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/101249","name":"101249","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-9625","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9625","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"9625","vulnerable":"1","versionEndIncluding":"1.0.0.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"envitech","cpe5":"envidas_ultimate","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-9625","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Envitech Ltd. EnviDAS Ultimate","version":{"version_data":[{"version_value":"Envitech Ltd. EnviDAS Ultimate"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settings or execute code remotely."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-287"}]}]},"references":{"reference_data":[{"name":"101249","refsource":"BID","url":"http://www.securityfocus.com/bid/101249"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-285-03","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-285-03"}]}},"nvd":{"publishedDate":"2017-10-17 22:29:00","lastModifiedDate":"2019-10-09 23:30:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":4.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:envitech:envidas_ultimate:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.0.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"9625","Ordinal":"106648","Title":"CVE-2017-9625","CVE":"CVE-2017-9625","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"9625","Ordinal":"1","NoteData":"An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settings or execute code remotely.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"9625","Ordinal":"2","NoteData":"2017-10-17","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"9625","Ordinal":"3","NoteData":"2017-10-18","Type":"Other","Title":"Modified"}]}}}