Vulnerability Description
An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settings or execute code remotely.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Envitech | Envidas Ultimate | <= 1.0.0.4 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101249Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-285-03Third Party AdvisoryUS Government ResourceVDB Entry
- http://www.securityfocus.com/bid/101249Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-285-03Third Party AdvisoryUS Government ResourceVDB Entry
FAQ
What is CVE-2017-9625?
CVE-2017-9625 is a vulnerability with a CVSS score of 8.2 (HIGH). An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view informati...
How severe is CVE-2017-9625?
CVE-2017-9625 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9625?
Check the references section above for vendor advisories and patch information. Affected products include: Envitech Envidas Ultimate.