CVE-2016-8354
published 2017-02-13CVE-2016-8354: An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator…
PriorityP428high7CVSS 3.0
AVLACHPRNUIRSUCHIHAH
EPSS
1.10%
62.0th percentile
An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the simulator execute malicious code by redirecting the control flow of these instructions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | unity_pro | <= 11.0 | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Unity PRO Control Flow Management Vulnerability
cisa_ics·2016-11-01
Schneider Electric Unity PRO Control Flow Management Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Unity PRO Control Flow Management Vulnerability
Last RevisedNovember 01, 2016
Alert CodeICSA-16-306-03
## OVERVIEW
Avihay Kain and Mille Gandelsman of Indegy have identified a vulnerability in Schneider Electric Unity PRO Software product. Schneider Electric has released a security notification with instructions to mitigate this vulnerability.
This vulnerability could be exploited remotely.
## AFFECTED PRODUCTS
Schneider Electric reports that the vulnerability affects the following versions of Unity PRO:
- Unity PRO, all versions prior to V11.1
## IMPACT
GHSA
GHSA-m337-hwf6-792v: An issue was discovered in Schneider Electric Unity PRO prior to V11
ghsa_unreviewed·2022-05-17
CVE-2016-8354 [HIGH] CWE-94 GHSA-m337-hwf6-792v: An issue was discovered in Schneider Electric Unity PRO prior to V11
An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the simulator execute malicious code by redirecting the control flow of these instructions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-13
Published