CVE-2017-12728

HIGH

SpiderControl SCADA Web Server < 2.02.0007 - Authenticated Privilege Escalation via Service Executable Modification

Title source: llm
STIX 2.1

Description

An Improper Privilege Management issue was discovered in SpiderControl SCADA Web Server Version 2.02.0007 and prior. Authenticated, non-administrative local users are able to alter service executables with escalated privileges, which could allow an attacker to execute arbitrary code under the context of the current system services.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-250-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100668

Scores

CVSS v3 7.8
EPSS 0.0039
EPSS Percentile 30.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (2)
n/a/SpiderControl SCADA Web Server SpiderControl SCADA Web Server
spidercontrol/scada_webserver < 2.02.0007
Published Oct 05, 2017
Tracked Since Feb 18, 2026