PT-2020-19208 · Eaton · Eaton'S 9000X Programming/Configuration

Published

2020-09-30

·

Updated

2020-10-16

·

CVE-2020-6654

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eaton's 9000x Programming and Configuration Software versions 2.0.38 and prior
Description A DLL Hijacking issue allows an attacker to execute arbitrary code by replacing required DLLs with malicious ones when the software attempts to load vci11un6.DLL and cinpl.DLL.
Recommendations For versions 2.0.38 and prior, consider restricting access to the vulnerable DLLs vci11un6.DLL and cinpl.DLL to minimize the risk of exploitation until a patch is available.

Fix

Uncontrolled Search Path Element

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6654

Affected Products

Eaton'S 9000X Programming/Configuration