PT-2024-6676 · Rockwell Automation · Emulate3D
Published
2024-06-17
·
Updated
2024-08-17
·
CVE-2024-6079
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Rockwell Automation Emulate3D version 17.00.00.13276
Description:
A vulnerability exists in the Rockwell Automation Emulate3D, which could be leveraged to execute a DLL Hijacking attack. The application loads shared libraries, which are readable and writable by any user. If exploited, a malicious user could leverage a malicious dll and perform a remote code execution attack. The issue is related to incorrect external control of the name or path of a .dll file when loading libraries.
Recommendations:
For Rockwell Automation Emulate3D version 17.00.00.13276, patch immediately to prevent potential system compromise. Monitor for signs of exploit and consider restricting access to shared libraries to minimize the risk of exploitation. As a temporary workaround, consider disabling the loading of shared libraries until a patch is available.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Emulate3D