← Vulnerability feed

Vulnerability record · CVE-2017-9962 · published 26 September 2017

CVE-2017-9962: Aveva clearscada memory buffer overflow vulnerability

Aveva · Clearscada

Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected behavior. Client applications affected include ViewX and the Server Icon.

7.5 CVSS 3.0 High EPSS 1.0% · top 37.6% CWE-119 · Memory buffer overflow
7.5CVSS 3.0 base score, v2 5.0
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected behavior. Client applications affected include ViewX and the Server Icon.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-9962 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-3143Aveva clearscada vulnerabilityUse-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9,…EPSS 7.5%7.5CVE-2017-6021Aveva clearscada improper input validation vulnerabilityIn Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 …EPSS 1.7%6.8CVE-2014-0779Aveva clearscada memory buffer overflow vulnerabilityThe PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R2 build 71.4…EPSS 1.5%6.4CVE-2014-5412Aveva clearscada improper authentication vulnerabilitySchneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access…EPSS 1.6%6.4CVE-2014-5413Aveva clearscada vulnerabilitySchneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easie…EPSS 1.0%4.9CVE-2014-5411Aveva clearscada cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote a…EPSS 1.3%4.3CVE-2013-6142Aveva clearscada vulnerabilityDNP3Driver.exe in the DNP3 driver in Schneider Electric ClearSCADA 2010 R2 through 2010 R3.1 and SCADA Expert ClearSCADA 2013 R1 through 2013 R1.2 al…EPSS 1.2%4.3CVE-2011-3144Aveva clearscada cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2017-9962), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.