PT-2024-6676 · Rockwell Automation · Emulate3D

Published

2024-06-17

·

Updated

2024-08-17

·

CVE-2024-6079

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Rockwell Automation Emulate3D version 17.00.00.13276
Description: A vulnerability exists in the Rockwell Automation Emulate3D, which could be leveraged to execute a DLL Hijacking attack. The application loads shared libraries, which are readable and writable by any user. If exploited, a malicious user could leverage a malicious dll and perform a remote code execution attack. The issue is related to incorrect external control of the name or path of a .dll file when loading libraries.
Recommendations: For Rockwell Automation Emulate3D version 17.00.00.13276, patch immediately to prevent potential system compromise. Monitor for signs of exploit and consider restricting access to shared libraries to minimize the risk of exploitation. As a temporary workaround, consider disabling the loading of shared libraries until a patch is available.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2024-07882
CVE-2024-6079

Affected Products

Emulate3D