CVE-2017-7916

MEDIUM

ABB Vsn300 Firmware < 1.8.15 - Improper Privilege Management

Title source: rule

Description

A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. A malicious user may be able to gain access to configuration information that should be restricted.

Scores

CVSS v3 6.5
EPSS 0.0028
EPSS Percentile 51.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-269 CWE-264
Status published
Products (3)
abb/vsn300_firmware < 1.8.15
abb/vsn300_for_react_firmware
n/a/ABB VSN300 WiFi Logger Card < ABB VSN300 WiFi Logger Card
Published Aug 07, 2017
Tracked Since Feb 18, 2026