Vulnerability Description
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permissions in conjunction with a lack of integrity and authenticity checks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Infotecs | Vipnet Client | <= 4.3.1 |
| Infotecs | Vipnet Coordinator | <= 4.3.1 |
Related Weaknesses (CWE)
References
- https://github.com/Houl777/CVE-2017-9606Third Party Advisory
- https://github.com/Houl777/CVE-2017-9606Third Party Advisory
FAQ
What is CVE-2017-9606?
CVE-2017-9606 is a vulnerability with a CVSS score of 7.3 (HIGH). Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorre...
How severe is CVE-2017-9606?
CVE-2017-9606 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9606?
Check the references section above for vendor advisories and patch information. Affected products include: Infotecs Vipnet Client, Infotecs Vipnet Coordinator.