PT-2017-9632 · Schneider Electric · Unity Pro

Avihay Kain

+1

·

Publicado

2017-02-13

·

Atualizado

2017-03-15

·

CVE-2016-8354

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Schneider Electric Unity PRO versions prior to V11.1
Description An issue was discovered where Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the simulator execute malicious code by redirecting the control flow of these instructions.
Recommendations For versions prior to V11.1, update to version V11.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the PLC Simulator to minimize the risk of exploitation. Avoid loading patched Unity project files onto the simulator until the issue is resolved.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8354

Produtos afetados

Unity Pro