CVE-2017-9640

MEDIUM ⚠ Exploit

A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; AL...

Affects 3 products across 2 vendors.

BCS6.6
CVSS 3.06.3
EPSS8.5%
Percentile94th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component.
CWE Weakness Definitions
CWE-22: Path Traversal

Attacker manipulates file path inputs to access files outside the intended directory.

Related Attack Patterns (CAPEC)
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
via CWE-22
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-22
CAPEC-78 Using Escaped Slashes in Alternate Encoding
via CWE-22
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-22
CAPEC-126 Path Traversal
via CWE-22

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2017. A medium severity vulnerability affects Automatedlogic systems (CVE-2017-9640). Public exploit code is available. Isolate affected systems if patching is not feasible.

BSID: BS-2017-GLOBAL-298580-M • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2017-9640?
This vulnerability was disclosed in 2017. A medium severity vulnerability affects Automatedlogic systems (CVE-2017-9640). Public exploit code is available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2017-9640?
CVE-2017-9640 has CVSS 6.3 (Medium). Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L. EPSS: 8.5%.
Is CVE-2017-9640 actively exploited?
Public exploit available for CVE-2017-9640. Exploitation risk elevated.
How do I remediate CVE-2017-9640?
Priority: MONITOR. Advisory: https://ics-cert.us-cert.gov/advisories/ICSA-17-234-01
What systems are affected by CVE-2017-9640?
CVE-2017-9640 affects: Automatedlogic, Automatedlogic, Carrier.
Vulnerability Details
CVE IDCVE-2017-9640
BSIDBS-2017-GLOBAL-298580-M BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Published2017-08-25
Last Modified2026-05-13
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software. CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Automatedlogic I-Vu
Automatedlogic Sitescan Web
Carrier Automatedlogic Webctrl
Remediation
View Vendor Advisory →

Remediation Priority: MONITOR

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 3256 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash7f398ec0cbce978f6c2281769e4c3021203483434dd0b72e307a0899f0b50741ec15c52d82c1e15eeb72479f0da48acfe28f65a89dad129fe27112196333cade
Related CVEs affecting Automatedlogic
CVE-2017-9650 7.8 An Unrestricted Upload of File with Dangerous Type issue was discovered in Au... CVE-2026-32666 7.5 WebCTRL systems that communicate over BACnet inherit the protocol's lack of ... CVE-2016-5795 7.3 An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert Site... CVE-2017-9644 7.0 An Unquoted Search Path or Element issue was discovered in Automated Logic Co... CVE-2021-31682 6.1 The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application ...
View all Automatedlogic CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →