CVE-2016-8354

CWE-94Code Injection3 documents3 sources
Severity
7.0HIGH
EPSS
0.2%
top 62.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13
Latest updateMay 17

Description

An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the simulator execute malicious code by redirecting the control flow of these instructions.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages2 packages

CVEListV5schneider_electric_unity_pro_control_prior_to_v11.1Schneider Electric Unity PRO Control prior to V11.1

🔴Vulnerability Details

2
GHSA
GHSA-m337-hwf6-792v: An issue was discovered in Schneider Electric Unity PRO prior to V112022-05-17
CVEList
CVE-2016-8354: An issue was discovered in Schneider Electric Unity PRO prior to V112017-02-13
CVE-2016-8354 (HIGH CVSS 7) | An issue was discovered in Schneide | cvebase.io