CVE-2017-6033
published 2017-04-07CVE-2017-6033: A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software…
PriorityP434high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.34%
68.0th percentile
A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | interactive_graphical_scada_system | <= 12.0 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Interactive Graphical SCADA System Software
cisa_ics·2017-04-04
Schneider Electric Interactive Graphical SCADA System Software
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Interactive Graphical SCADA System Software
Last RevisedApril 04, 2017
Alert CodeICSA-17-094-01
## CVSS v3 6.8
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Schneider Electric
Equipment: Interactive Graphical SCADA System (IGSS) Software
Vulnerability: DLL Hijacking
## AFFECTED PRODUCTS
Schneider Electric reports that the vulnerability affects the following IGSS HMI desktop application:
- IGSS Software, Version 12 and previous versions.
## IMPACT
An attacker who exploits this vulnerability may be able to remotely execute arbitrary
GHSA
GHSA-9hvm-ch4q-jqmr: A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions
ghsa_unreviewed·2022-05-13
CVE-2017-6033 [HIGH] CWE-427 GHSA-9hvm-ch4q-jqmr: A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions
A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path.
No detection rules found.
No public exploits indexed.
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2017-090-01http://www.securityfocus.com/bid/97389https://ics-cert.us-cert.gov/advisories/ICSA-17-094-01http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2017-090-01http://www.securityfocus.com/bid/97389https://ics-cert.us-cert.gov/advisories/ICSA-17-094-01
2017-04-07
Published