AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-9664

CRITICAL · CVSS 9.8 EPSS 2.62% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-05-24 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2017-9664
Severity
CRITICAL
CVSS
9.8
EPSS
2.62%

Original NVD Description

In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker may access internal files of ABB SREA-01 and SREA-50 legacy remote monitoring tools without any authorization over the network using a HTTP request which refers to files using ../../ relative paths. Once the internal password file is retrieved, the password hash can be identified using a brute force attack. There is also an exploit allowing running of commands after authorization.