CVE-2017-6869
A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web server by sending specially crafted network packets to port 443/TCP or port 80/TCP.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.98% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- siemens/viewport for web office portal
- Source
- productcert@siemens.com
References
- http://www.securityfocus.com/bid/99343Third Party Advisory, VDB Entry
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-545214.pdfVendor Advisory
- http://www.securityfocus.com/bid/99343Third Party Advisory, VDB Entry
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-545214.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.