PT-2017-9632 · Schneider Electric · Unity Pro
Avihay Kain
+1
·
Published
2017-02-13
·
Updated
2017-03-15
·
CVE-2016-8354
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Schneider Electric Unity PRO versions prior to V11.1
Description
An issue was discovered where Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the simulator execute malicious code by redirecting the control flow of these instructions.
Recommendations
For versions prior to V11.1, update to version V11.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the PLC Simulator to minimize the risk of exploitation. Avoid loading patched Unity project files onto the simulator until the issue is resolved.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unity Pro