CVE-2017-7920

HIGH

ABB VSN300 WiFi Logger Card <=1.8.15 & VSN300 for React <=2.1.3 - Unauthenticated Information Disclosure

Title source: llm
STIX 2.1

Description

An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access internal information about status and connected devices without authenticating.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99558
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-192-03

Scores

CVSS v3 7.5
EPSS 0.0140
EPSS Percentile 80.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (3)
abb/vsn300_firmware < 1.8.15
abb/vsn300_for_react_firmware 2.1.3
n/a/ABB VSN300 WiFi Logger Card ABB VSN300 WiFi Logger Card
Published Aug 07, 2017
Tracked Since Feb 18, 2026