{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T13:22:42.210","vulnerabilities":[{"cve":{"id":"CVE-2017-9625","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2017-10-17T22:29:00.463","lastModified":"2026-06-17T01:28:36.380","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settings or execute code remotely."},{"lang":"es","value":"Se detectó un problema de autenticación incorrecta en Envitech EnviDAS Ultimate en versiones anteriores a la v1.0.0.5. La aplicación web carece de autenticación correcta, lo que puede permitir que un atacante visualice información y modifique configuraciones o ejecute código remotamente."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"n/a","product":"Envitech Ltd. EnviDAS Ultimate","versions":[{"version":"Envitech Ltd. EnviDAS Ultimate","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:envitech:envidas_ultimate:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.0.4","matchCriteriaId":"4959666A-4E1D-45B2-854F-95DB0D84A2A3"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/101249","source":"ics-cert@hq.dhs.gov","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-285-03","source":"ics-cert@hq.dhs.gov","tags":["Third Party Advisory","US Government Resource","VDB Entry"]},{"url":"http://www.securityfocus.com/bid/101249","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-17-285-03","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource","VDB Entry"]}]}}]}