{"api_version":"1","generated_at":"2026-07-23T11:05:19+00:00","cve":"CVE-2017-9636","urls":{"html":"https://cve.report/CVE-2017-9636","api":"https://cve.report/api/cve/CVE-2017-9636.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-9636","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-9636"},"summary":{"title":"CVE-2017-9636","description":"Mitsubishi E-Designer, Version 7.52 Build 344 contains five code sections which may be exploited to overwrite the heap. This can result in arbitrary code execution, compromised data integrity, denial of service, and system crash.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2018-04-17 14:29:00","updated_at":"2019-10-09 23:30:00"},"problem_types":["CWE-119"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/100097","name":"100097","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-213-01","name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-213-01","refsource":"MISC","tags":["Third Party Advisory","US Government Resource"],"title":"Mitsubishi Electric Europe B.V. E-Designer | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-9636","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9636","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"9636","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mitsubishielectric","cpe5":"e-designer","cpe6":"7.52","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"9636","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mitsubishielectric","cpe5":"e-designer","cpe6":"7.52","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","DATE_PUBLIC":"2017-08-01T00:00:00","ID":"CVE-2017-9636","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"E-Designer","version":{"version_data":[{"version_value":"Version 7.52 Build 344."}]}}]},"vendor_name":"Mitsubishi Electric Europe B.V."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Mitsubishi E-Designer, Version 7.52 Build 344 contains five code sections which may be exploited to overwrite the heap. This can result in arbitrary code execution, compromised data integrity, denial of service, and system crash."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Heap based buffer overflow CWE-122"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-17-213-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-213-01"},{"name":"100097","refsource":"BID","url":"http://www.securityfocus.com/bid/100097"}]}},"nvd":{"publishedDate":"2018-04-17 14:29:00","lastModifiedDate":"2019-10-09 23:30:00","problem_types":["CWE-119"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mitsubishielectric:e-designer:7.52:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"9636","Ordinal":"106659","Title":"CVE-2017-9636","CVE":"CVE-2017-9636","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"9636","Ordinal":"1","NoteData":"Mitsubishi E-Designer, Version 7.52 Build 344 contains five code sections which may be exploited to overwrite the heap. This can result in arbitrary code execution, compromised data integrity, denial of service, and system crash.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"9636","Ordinal":"2","NoteData":"2018-04-17","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"9636","Ordinal":"3","NoteData":"2018-04-18","Type":"Other","Title":"Modified"}]}}}