PT-2017-13187 · I Sens · I-Sens Smartlog Diabetes Management

Publicado

2017-10-04

·

Atualizado

2019-10-09

·

CVE-2017-13993

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions i-SENS SmartLog Diabetes Management Software versions 2.4.0 and prior
Description An Uncontrolled Search Path or Element issue was discovered, which could be exploited by placing a specially crafted DLL file in the search path, allowing an attacker to execute arbitrary code on the system if the malicious DLL is loaded prior to the valid DLL.
Recommendations For i-SENS SmartLog Diabetes Management Software versions 2.4.0 and prior, consider restricting access to the search path to prevent malicious DLL files from being loaded, until a patch or fix is available.

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-13993

Produtos afetados

I-Sens Smartlog Diabetes Management