Show plain JSON{"id": "CVE-2017-1000230", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "NONE"}, "acInsufInfo": true, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2017-11-17T21:29:00.357", "references": [{"url": "https://sourceforge.net/p/snap7/discussion/bugfix/thread/2d2d085c/", "tags": ["Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://sourceforge.net/p/snap7/discussion/bugfix/thread/2d2d085c/", "tags": ["Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-20"}]}], "descriptions": [{"lang": "en", "value": "The Snap7 Server version 1.4.1 can be crashed when the ItemCount field of the ReadVar or WriteVar functions of the S7 protocol implementation in Snap7 are provided with unexpected input, thus resulting in denial of service attack."}, {"lang": "es", "value": "El servidor Snap7 en su versi\u00f3n 1.4.1 puede sufrir un cierre inesperado cuando se proporciona valores de entrada inesperados en el campo ItemCount de las funciones ReadVar o WriteVar de la implementaci\u00f3n del protocolo S7 en Snap7, , lo que da lugar a un ataque de denegaci\u00f3n de servicio (DoS)."}], "lastModified": "2025-04-20T01:37:25.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:snap7_project:snap7_server:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3071328F-CF81-409E-8213-133FF2CACCB1"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}