{"api_version":"1","generated_at":"2026-04-22T19:34:50+00:00","cve":"CVE-2017-9942","urls":{"html":"https://cve.report/CVE-2017-9942","api":"https://cve.report/api/cve/CVE-2017-9942.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-9942","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-9942"},"summary":{"title":"CVE-2017-9942","description":"A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.","state":"PUBLIC","assigner":"productcert@siemens.com","published_at":"2017-08-08 00:29:00","updated_at":"2019-10-09 23:30:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/99578","name":"99578","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-339433.pdf","name":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-339433.pdf","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Siemens","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-9942","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9942","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"9942","vulnerable":"1","versionEndIncluding":"2.65","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"siemens","cpe5":"sipass_integrated","cpe6":"*","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"productcert@siemens.com","ID":"CVE-2017-9942","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"SiPass integrated All versions before V2.70","version":{"version_data":[{"version_value":"SiPass integrated All versions before V2.70"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-257: Storing Passwords in a Recoverable Format"}]}]},"references":{"reference_data":[{"name":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-339433.pdf","refsource":"CONFIRM","url":"https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-339433.pdf"},{"name":"99578","refsource":"BID","url":"http://www.securityfocus.com/bid/99578"}]}},"nvd":{"publishedDate":"2017-08-08 00:29:00","lastModifiedDate":"2019-10-09 23:30:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:siemens:sipass_integrated:*:sp2:*:*:*:*:*:*","versionEndIncluding":"2.65","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"9942","Ordinal":"107582","Title":"CVE-2017-9942","CVE":"CVE-2017-9942","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"9942","Ordinal":"1","NoteData":"A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"9942","Ordinal":"2","NoteData":"2017-08-07","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"9942","Ordinal":"3","NoteData":"2017-08-08","Type":"Other","Title":"Modified"}]}}}