SpiderControl SCADA Web Server CVE-2017-12728 Local Code Execution Vulnerability
BID:100668
CVE-2017-12728 |Info
SpiderControl SCADA Web Server CVE-2017-12728 Local Code Execution Vulnerability
| Bugtraq ID: | 100668 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-12728 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 07 2017 12:00AM |
| Updated: | Sep 07 2017 12:00AM |
| Credit: | Karn Ganeshen. |
| Vulnerable: |
SpiderControl SCADA Web Server 2.2.7 SpiderControl SCADA Web Server 0 |
| Not Vulnerable: |
SpiderControl SCADA Web Server 2.02.0100 |
Discussion
SpiderControl SCADA Web Server CVE-2017-12728 Local Code Execution Vulnerability
SpiderControl SCADA Web Server is prone to a local code-execution vulnerability.
A local attacker can leverage this issue to execute arbitrary code in the context of affected application. Failed attempts may lead to denial-of-service conditions.
SCADA Web Server Version 2.02.0007 and prior are vulnerable.
SpiderControl SCADA Web Server is prone to a local code-execution vulnerability.
A local attacker can leverage this issue to execute arbitrary code in the context of affected application. Failed attempts may lead to denial-of-service conditions.
SCADA Web Server Version 2.02.0007 and prior are vulnerable.
Exploit / POC
SpiderControl SCADA Web Server CVE-2017-12728 Local Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SpiderControl SCADA Web Server CVE-2017-12728 Local Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SpiderControl SCADA Web Server CVE-2017-12728 Local Code Execution Vulnerability
References:
References:
- SpiderControl Home Page (SpiderControl)
- ICSA-17-250-01:SpiderControl SCADA Web Server (CERT)