CVE-2017-9644
Severity CVSS v4.0:
Pending analysis
Type:
CWE-428
Unquoted Search Path or Element
Publication date:
25/08/2017
Last modified:
20/04/2025
Description
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.
Impact
Base Score 3.x
7.00
Severity 3.x
HIGH
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:* | 5.2 (including) | |
| cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:* | 5.5 (including) | |
| cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:* | 6.0 (including) | |
| cpe:2.3:a:automatedlogic:i-vu:*:*:*:*:*:*:*:* | 6.5 (including) | |
| cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:* | 5.2 (including) | |
| cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:* | 5.5 (including) | |
| cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:* | 6.1 (including) | |
| cpe:2.3:a:automatedlogic:sitescan_web:*:*:*:*:*:*:*:* | 6.5 (including) | |
| cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:* | 5.2 (including) | |
| cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:* | 5.5 (including) | |
| cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:* | 6.0 (including) | |
| cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:* | 6.1 (including) | |
| cpe:2.3:a:carrier:automatedlogic_webctrl:*:*:*:*:*:*:*:* | 6.5 (including) |
To consult the complete list of CPE names with products and versions, see this page



