PT-2020-19208 · Eaton · Eaton'S 9000X Programming/Configuration
Published
2020-09-30
·
Updated
2020-10-16
·
CVE-2020-6654
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eaton's 9000x Programming and Configuration Software versions 2.0.38 and prior
Description
A DLL Hijacking issue allows an attacker to execute arbitrary code by replacing required DLLs with malicious ones when the software attempts to load
vci11un6.DLL and cinpl.DLL.Recommendations
For versions 2.0.38 and prior, consider restricting access to the vulnerable DLLs
vci11un6.DLL and cinpl.DLL to minimize the risk of exploitation until a patch is available.Fix
Uncontrolled Search Path Element
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eaton'S 9000X Programming/Configuration