CVE-2017-9644

HIGH ⚠ Exploit

An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-V...

Affects 3 products across 2 vendors.

BCS6.82
CVSS 3.07.0
EPSS1.4%
Percentile70th
PatchPatched
CVSS Vector — Plain English Requires local access, high complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-428: CWE-428
◆ SAGE Intelligence — CITED Relevance Research Team

{ "executive_summary": "An unquoted search path vulnerability exists in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web versions prior to 6.5, 6.1, 6.0, 5.5, and 5.2. This could allow a non-privileged local attacker to execute arbitrary code with elevated privileges.", "attack_vector_detail": "The vulnerability arises from the application using an unquoted search path for executable files. An attacker can place a malicious executable in a directory that is included in the search path, which the application will then execute instead of the intended file.", "affected_components": ["ALC WebCTRL", "i-Vu", "SiteScan Web 6.5 and prior", "ALC WebCTRL, SiteScan Web 6.1 and prior", "ALC WebCTRL, i-Vu 6.0 and prior", "ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior", "ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior"], "exploitation_likelihood": "MEDIUM", "remediation_priority":

BSID: BS-2017-GLOBAL-171331-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2017-9644?
{ "executive_summary": "An unquoted search path vulnerability exists in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web versions prior to 6.5, 6.1, 6.0, 5.5, and 5.2. This could allow a non-privileged local attacker to execute arbitrary code with elevated privileges.", "attack_vector_detail": "The vulnerability arises from the application using an unquoted search path for executable files. An attacker can place a malicious executable in a directory that is included in the s
What is the CVSS score for CVE-2017-9644?
CVE-2017-9644 has CVSS 7.0 (High). Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.4%.
Is CVE-2017-9644 actively exploited?
Public exploit available for CVE-2017-9644. Exploitation risk elevated.
How do I remediate CVE-2017-9644?
Advisory: https://ics-cert.us-cert.gov/advisories/ICSA-17-234-01
What systems are affected by CVE-2017-9644?
CVE-2017-9644 affects: Automatedlogic, Automatedlogic, Carrier.
Vulnerability Details
CVE IDCVE-2017-9644
BSIDBS-2017-GLOBAL-171331-H BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2017-08-25
Last Modified2026-05-13
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Automatedlogic I-Vu
Automatedlogic Sitescan Web
Carrier Automatedlogic Webctrl
Remediation
View Vendor Advisory →
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 3256 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
Enriched At2026-05-25
Related CVEs affecting Automatedlogic
CVE-2017-9650 7.8 An Unrestricted Upload of File with Dangerous Type issue was discovered in Au... CVE-2026-32666 7.5 WebCTRL systems that communicate over BACnet inherit the protocol's lack of ... CVE-2016-5795 7.3 An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert Site... CVE-2017-9640 6.3 A Path Traversal issue was discovered in Automated Logic Corporation (ALC) AL... CVE-2021-31682 6.1 The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application ...
View all Automatedlogic CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →