CVE-2017-14852
8.6 HIGHAn insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SS...
Published: 2019-06-03 · Last updated: 2026-06-02
Severity and scoring
- CVSS
- 8.6 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
- CWE
- CWE-310, CWE-311
Affected products
| Vendor | Product |
|---|---|
| orpak | siteomat |
Description
An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2017-14852
- [Vendor advisory]http://www.orpak.com
- [Other]http://www.securityfocus.com/bid/108167
- [Other]https://ics-cert.us-cert.gov/advisories/ICSA-19-122-01
- [Vendor advisory]http://www.orpak.com
- [Other]http://www.securityfocus.com/bid/108167
- [Other]https://ics-cert.us-cert.gov/advisories/ICSA-19-122-01
Related CVEs
Same vendor
- CVE-2017-14854 — A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution (9.1 CRITICAL)
- CVE-2017-14853 — The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses ... (8.6 HIGH)
- CVE-2017-14851 — A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25 (9.8 CRITICAL)
- CVE-2017-14850 — All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to... (6.1 MEDIUM)
- CVE-2017-14728 — An authentication bypass was found in an unknown area of the SiteOmat source code (9.8 CRITICAL)
Same CWE
- CVE-2026-53442 — Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job c... (5.3 MEDIUM)
- CVE-2026-49000 — An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management... (7.0 HIGH)
- CVE-2026-34486 — Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptI... (7.5 HIGH)
- CVE-2025-13453 — A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on t... (4.6 MEDIUM)
- CVE-2020-7567 — A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the ... (5.7 MEDIUM)