CVE-2017-9634 is a critical vulnerability affecting Mitsubishi E-Designer, Version 7.52 Build 344, where two code sections allow attackers to overwrite arbitrary memory locations. This flaw carries a CVSS score of 9.8 (Critical) due to its network-exploitable nature with low attack complexity, enabling arbitrary code execution, data integrity compromise, denial of service, and system crashes. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not in the KEV catalog, the vulnerability has garnered some community discussion and media coverage, indicating awareness despite no active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.52CPE matchmatch criteria | cpe:2.3:a:mitsubishielectric:e-designer:7.52:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.