CVE-2017-16731

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/12/2017
Last modified:
20/04/2025

Description

An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to LDAP/AD using the LDAP protocol. An attacker could exploit the vulnerability by sniffing local network traffic, allowing the discovery of authentication credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hitachienergy:ellipse:*:*:*:*:*:*:*:* 8.3.0 (including) 8.9.0 (including)