CVE-2019-6825
published 2019-07-15CVE-2019-6825: A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL file, with…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.20%
64.6th percentile
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL file, with the same name of any resident DLLs inside the software installation, to execute arbitrary code in all versions of ProClima prior to version 8.0.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| proclima | proclima_all_versions_prior_to_version_8.0.0 | — | — |
| schneider-electric | proclima | < 8.0.0 | 8.0.0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric ProClima
cisa_ics·2019-10-22·CVSS 9.8
[CRITICAL] Schneider Electric ProClima
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric ProClima
Last RevisedOctober 22, 2019
Alert CodeICSA-19-295-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Schneider Electric
- Equipment: Proclima
- Vulnerabilities: Code Injection, Improper Restriction of Operations within the Bounds of a Memory Buffer, Uncontrolled Search Path Element
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
## 3. TECHNICAL DETAILS
## 3.1 AFFE
GHSA
GHSA-fvg2-944m-v7hq: A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8
ghsa_unreviewed·2022-05-24
CVE-2019-6825 [HIGH] CWE-427 GHSA-fvg2-944m-v7hq: A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL file, with the same name of any resident DLLs inside the software installation, to execute arbitrary code in all versions of ProClima prior to version 8.0.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-15
Published