CVE-2019-6823
published 2019-07-15CVE-2019-6823: A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker to…
PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.95%
91.2th percentile
A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| proclima | proclima_all_versions_prior_to_version_8.0.0 | — | — |
| schneider-electric | proclima | < 8.0.0 | 8.0.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2019-6823 is a Code Injection (CWE-94) vulnerability in Schneider Electric ProClima affecting all versions prior to 8.0.0, exploitable remotely by an unauthenticated attacker with low skill level (CVSS v3 8.8, AV:N/AC:L/PR:N/UI:R). ↗
- →CVE-2019-6825 (related, same advisory) is an Uncontrolled Search Path Element (CWE-427) — a malicious DLL with the same name as a resident DLL in the ProClima installation directory can lead to arbitrary code execution. Monitor for unexpected DLL loads from non-standard paths in the ProClima install directory. ↗
- →No known public exploits specifically target these vulnerabilities as of the advisory date (October 22, 2019). ↗
- ·All versions of ProClima prior to 8.0.0 are affected. Version 8.0.0 and newer are patched. Ensure deployed instances are identified and upgraded. ↗
- ·CVE-2019-6823 has UI:R in its CVSS vector, meaning user interaction is required for exploitation — factor this into threat modelling (e.g., phishing/social engineering delivery vector). ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric ProClima
cisa_ics·2019-10-22·CVSS 9.8
[CRITICAL] Schneider Electric ProClima
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric ProClima
Last RevisedOctober 22, 2019
Alert CodeICSA-19-295-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Schneider Electric
- Equipment: Proclima
- Vulnerabilities: Code Injection, Improper Restriction of Operations within the Bounds of a Memory Buffer, Uncontrolled Search Path Element
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
## 3. TECHNICAL DETAILS
## 3.1 AFFE
GHSA
GHSA-7w73-hxcj-rf46: A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8
ghsa_unreviewed·2022-05-24
CVE-2019-6823 [CRITICAL] CWE-94 GHSA-7w73-hxcj-rf46: A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8
A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-15
Published