Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-5178

Quick assessment

Affected
n/a Schneider Electric Wonderware Intelligence 2014R3 and prior
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Schneider Electric Wonderware Intelligence是法国施耐德电气(Schneider Electric)公司一套工业大数据智能管理解决方案。该解决方案对工业大数据提供可视化的查询和分析等功能。Electric Tableau Server/Desktop是其中的服务器端和桌面。 Schneider Electric Wonderware Intelligence 2014R3及之前的版本中的Schneider Electric Tableau Server/Deskto

AI Predicted 8.1 Difficulty: Easy EPSS 10.48% · P95
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-5178

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and prior. These versions contain a system account that is installed by default. The default system account is difficult to configure with non-default credentials after installation, and changing the default credentials in the embedded Tableau Server is not documented. If Tableau Server is used with Windows integrated security (Active Directory), the software is not vulnerable. However, when Tableau Server is used with local authentication mode, the software is vulnerable. The default system account could be used to gain unauthorized access.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Schneider Electric Wonderware Intelligence Electric Tableau Server/Desktop 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Schneider Electric Wonderware Intelligence是法国施耐德电气(Schneider Electric)公司一套工业大数据智能管理解决方案。该解决方案对工业大数据提供可视化的查询和分析等功能。Electric Tableau Server/Desktop是其中的服务器端和桌面。 Schneider Electric Wonderware Intelligence 2014R3及之前的版本中的Schneider Electric Tableau Server/Deskto
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- Schneider Electric Wonderware Intelligence 2014R3 and prior Schneider Electric Wonderware Intelligence 2014R3 and prior -

II. Public POCs for CVE-2017-5178

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-5178

登录查看更多情报信息。

Vendor Advisories for CVE-2017-5178 (1)

Other References for CVE-2017-5178 (2)

Same Patch Batch · n/a · 2017-03-08 · 13 CVEs total

CVE-2017-6543 Tenable Network Security Tenable Nessus 安全漏洞
CVE-2017-6544 Wuhu 跨站脚本漏洞
CVE-2017-6533 webpagetest 跨站脚本漏洞
CVE-2017-6534 webpagetest 跨站脚本漏洞
CVE-2017-6535 webpagetest 跨站脚本漏洞
CVE-2017-6536 webpagetest 跨站脚本漏洞
CVE-2017-6537 webpagetest 跨站脚本漏洞
CVE-2017-6538 webpagetest 跨站脚本漏洞
CVE-2017-6539 webpagetest 跨站脚本漏洞
CVE-2017-6540 webpagetest 跨站脚本漏洞
CVE-2017-6541 webpagetest 跨站脚本漏洞
CVE-2017-6518 SANADATA SanaCMS 跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2017-5178

No comments yet


Leave a comment