A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/103022 | Third Party Advisory VDB Entry |
https://www.schneider-electric.com/en/download/document/SEVD-2018-037-01/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: schneider
Published: 2018-02-12T00:00:00
Updated: 2018-02-15T10:57:01
Reserved: 2017-06-26T00:00:00
Link: CVE-2017-9967
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-02-12T23:29:00.307
Modified: 2019-10-03T00:03:26.223
Link: CVE-2017-9967
JSON object: View
Redhat Information
No data.
CWE