CVE-2017-9644
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-V...
Affects 3 products across 2 vendors.
{ "executive_summary": "An unquoted search path vulnerability exists in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web versions prior to 6.5, 6.1, 6.0, 5.5, and 5.2. This could allow a non-privileged local attacker to execute arbitrary code with elevated privileges.", "attack_vector_detail": "The vulnerability arises from the application using an unquoted search path for executable files. An attacker can place a malicious executable in a directory that is included in the search path, which the application will then execute instead of the intended file.", "affected_components": ["ALC WebCTRL", "i-Vu", "SiteScan Web 6.5 and prior", "ALC WebCTRL, SiteScan Web 6.1 and prior", "ALC WebCTRL, i-Vu 6.0 and prior", "ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior", "ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior"], "exploitation_likelihood": "MEDIUM", "remediation_priority":
BSID: BS-2017-GLOBAL-171331-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2017-9644?
What is the CVSS score for CVE-2017-9644?
Is CVE-2017-9644 actively exploited?
How do I remediate CVE-2017-9644?
What systems are affected by CVE-2017-9644?
| CVE ID | CVE-2017-9644 |
|---|---|
| BSID | BS-2017-GLOBAL-171331-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Published | 2017-08-25 |
| Last Modified | 2026-05-13 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.
Source: NIST NVD / MITRE CVE Database
| Vendor | Product | Fixed Version |
|---|---|---|
| Automatedlogic | I-Vu | — |
| Automatedlogic | Sitescan Web | — |
| Carrier | Automatedlogic Webctrl | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Enriched At | 2026-05-25 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →