Vulnerability Details CVE-2017-7920
An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access internal information about status and connected devices without authenticating.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.014
EPSS Ranking 79.6%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-7920
-
-
cpe:2.3:h:abb:vsn300_for_react:-
-
cpe:2.3:o:abb:vsn300_firmware:1.8.15
-
cpe:2.3:o:abb:vsn300_for_react_firmware:2.1.3