CVE-2016-5795

HIGH

An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker c...

Affects 3 products across 2 vendors.

BCS5.48
CVSS 3.07.3
EPSS2.2%
Percentile81th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component.
CWE Weakness Definitions
CWE-611: CWE-611
Related Attack Patterns (CAPEC)
CAPEC-221 Data Serialization External Entities Blowup
via CWE-611

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2017. A high severity vulnerability affects Automatedlogic systems (CVE-2016-5795). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2017-GLOBAL-233551-H • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2016-5795?
This vulnerability was disclosed in 2017. A high severity vulnerability affects Automatedlogic systems (CVE-2016-5795). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2016-5795?
CVE-2016-5795 has CVSS 7.3 (High). Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L. EPSS: 2.2%.
Is CVE-2016-5795 actively exploited?
No confirmed active exploitation of CVE-2016-5795 as of 2026-05-30.
How do I remediate CVE-2016-5795?
Priority: MEDIUM. Advisory: https://ics-cert.us-cert.gov/advisories/ICSA-17-150-01
What systems are affected by CVE-2016-5795?
CVE-2016-5795 affects: Automatedlogic, Automatedlogic, Carrier.
Vulnerability Details
CVE IDCVE-2016-5795
BSIDBS-2017-GLOBAL-233551-H BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Published2017-08-31
Last Modified2026-05-13
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious input to WebCTRL, i-Vu, or SiteScan Web through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious input to WebCTRL, i-Vu, or SiteScan Web through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network. CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Automatedlogic I-Vu
Automatedlogic Sitescan Web
Carrier Automatedlogic Webctrl
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 3250 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash1f7e321d54b459b354af316151d3926dc2d70ad48fa3d546dac0efd415adaab93e9a1450b9c9f5b2beac558c9658fa9cd0463dd7c871a166f3da8a136f41b2a0
Related CVEs affecting Automatedlogic
CVE-2017-9650 7.8 An Unrestricted Upload of File with Dangerous Type issue was discovered in Au... CVE-2026-32666 7.5 WebCTRL systems that communicate over BACnet inherit the protocol's lack of ... CVE-2017-9644 7.0 An Unquoted Search Path or Element issue was discovered in Automated Logic Co... CVE-2017-9640 6.3 A Path Traversal issue was discovered in Automated Logic Corporation (ALC) AL... CVE-2021-31682 6.1 The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application ...
View all Automatedlogic CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →