A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code execution on the system running Vijeo Basic when a malicious DLL library is loaded by the Product.
oryginał ENCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSchneider Electric Vijeo Designer
APPSchneider-Electric1.16.9≤ 1.0≤ 6.2
Powiązane podatności
Path Traversal w produktach Schneider Electric Harmony HMI via FTP
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of conf...
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base...
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause ...
A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prio...