PT-2017-13187 · I Sens · I-Sens Smartlog Diabetes Management
Publicado
2017-10-04
·
Atualizado
2019-10-09
·
CVE-2017-13993
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
i-SENS SmartLog Diabetes Management Software versions 2.4.0 and prior
Description
An Uncontrolled Search Path or Element issue was discovered, which could be exploited by placing a specially crafted DLL file in the search path, allowing an attacker to execute arbitrary code on the system if the malicious DLL is loaded prior to the valid DLL.
Recommendations
For i-SENS SmartLog Diabetes Management Software versions 2.4.0 and prior, consider restricting access to the search path to prevent malicious DLL files from being loaded, until a patch or fix is available.
Correção
Uncontrolled Search Path Element
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
I-Sens Smartlog Diabetes Management