PT-2016-6003 · Schneider Electric · Somachine Hvac Programming

Andrea Micalizzi

·

Publicado

2016-07-15

·

Atualizado

2022-02-03

·

CVE-2016-4529

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Schneider Electric SoMachine HVAC Programming Software for M171/M172 Controllers versions prior to 2.1.0
Description The issue allows remote attackers to execute arbitrary code via unknown vectors, related to the INTERFACESAFE FOR UNTRUSTED CALLER flag. This is due to an unspecified ActiveX control in the software.
Recommendations For versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue. As a temporary workaround, consider disabling the use of ActiveX controls until a patch is applied. Restrict access to the affected software to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2016-4529
ZDI-16-440

Produtos afetados

Somachine Hvac Programming