CVE-2017-14017

HIGH

Progea Movicon <11.5.1181 - Code Injection

Title source: llm
STIX 2.1

Description

An Uncontrolled Search Path Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An uncontrolled search path element vulnerability has been identified, which may allow a remote attacker without privileges to execute arbitrary code in the form of a malicious DLL file.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101483
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-290-01

Scores

CVSS v3 7.8
EPSS 0.0067
EPSS Percentile 47.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (2)
n/a/Progea Movicon SCADA/HMI Progea Movicon SCADA/HMI
progea/movicon < 11.5.1181
Published Oct 19, 2017
Tracked Since Feb 18, 2026