CVE-2017-9644 is an Unquoted Search Path vulnerability affecting multiple versions of Automated Logic Corporation's ALC WebCTRL, i-Vu, and SiteScan Web building automation systems. A local, non-privileged attacker could exploit this flaw to modify installation directory files and execute arbitrary code with elevated privileges. With a CVSS score of 7.0 (HIGH), this vulnerability has high impact on confidentiality, integrity, and availability, though it requires high attack complexity. While not currently on CISA's KEV catalog, an exploit is publicly available on ExploitDB, and it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.2CPE matchmatch criteria | cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:* | ||
<= 5.5CPE matchmatch criteria | cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:* | ||
<= 6.0CPE matchmatch criteria | cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:* | ||
<= 6.5CPE matchmatch criteria | cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:* | ||
<= 5.2CPE matchmatch criteria | cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.