CVE-2017-9650

HIGH ⚠ Exploit

An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ...

Affects 3 products across 2 vendors.

BCS7.3
CVSS 3.07.8
EPSS2.4%
Percentile82th
PatchPatched
CVSS Vector — Plain English Requires local access, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-434: Unrestricted Upload of File with Dangerous Type

Application allows file uploads without validating type, enabling upload of executable code or web shells.

Related Attack Patterns (CAPEC)
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
via CWE-434

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

An Unrestricted Upload of File with Dangerous Type vulnerability in Automated Logic Corporation (ALC) products allows an authenticated attacker to upload malicious files, potentially leading to remote code execution.

BSID: BS-2017-GLOBAL-278024-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2017-9650?
An Unrestricted Upload of File with Dangerous Type vulnerability in Automated Logic Corporation (ALC) products allows an authenticated attacker to upload malicious files, potentially leading to remote code execution.
What is the CVSS score for CVE-2017-9650?
CVE-2017-9650 has CVSS 7.8 (High). Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 2.4%.
Is CVE-2017-9650 actively exploited?
Public exploit available for CVE-2017-9650. Exploitation risk elevated.
How do I remediate CVE-2017-9650?
Priority: IMMEDIATE. Advisory: https://ics-cert.us-cert.gov/advisories/ICSA-17-234-01
What systems are affected by CVE-2017-9650?
CVE-2017-9650 affects: Automatedlogic, Automatedlogic, Carrier.
Vulnerability Details
CVE IDCVE-2017-9650
BSIDBS-2017-GLOBAL-278024-H BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2017-08-25
Last Modified2026-05-13
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from the lack of proper file type validation during the file upload process. An attacker with valid credentials can exploit this to upload a file with a dangerous type, such as a PHP script, which could then be executed on the server.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Automatedlogic I-Vu
Automatedlogic Sitescan Web
Carrier Automatedlogic Webctrl
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 3256 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Automatedlogic
CVE-2026-32666 7.5 WebCTRL systems that communicate over BACnet inherit the protocol's lack of ... CVE-2016-5795 7.3 An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert Site... CVE-2017-9644 7.0 An Unquoted Search Path or Element issue was discovered in Automated Logic Co... CVE-2017-9640 6.3 A Path Traversal issue was discovered in Automated Logic Corporation (ALC) AL... CVE-2021-31682 6.1 The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application ...
View all Automatedlogic CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →