VulnerabilityModified
CVE-2017-9625
An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5.
HIGH 8.2EPSS 2.30%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settings or execute code remotely.
- CVSS 3.0
- 8.2 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- EPSS
- 2.30% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- envitech/envidas ultimate
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/101249Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-285-03Third Party Advisory, US Government Resource, VDB Entry
- http://www.securityfocus.com/bid/101249Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-285-03Third Party Advisory, US Government Resource, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.