CVE-2017-7967 is a memory corruption vulnerability affecting Schneider Electric VAMPSET software versions prior to 2.2.189. This flaw allows a local attacker to cause the software to halt or fail to start by opening a specially crafted, corrupted vf2 file, though the Windows OS remains operational. Rated Medium (CVSS 5.5), the vulnerability requires local access and user interaction to open the malicious file, resulting in high availability impact to the VAMPSET software but no impact to connected protection relays. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, with only one media article covering the patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.185CPE matchmatch criteria | cpe:2.3:a:schneider-electric:vampset:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.