A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in all versions prior to 2.6.2 which could allow an attacker to execute arbitrary code.
References
| Link | Resource |
|---|---|
| http://www.securityfocus.com/bid/103338 | Third Party Advisory VDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-065-02 | Third Party Advisory US Government Resource |
| https://www.schneider-electric.com/en/download/document/SEVD-2018-060-01/ | Vendor Advisory |
| http://www.securityfocus.com/bid/103338 | Third Party Advisory VDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-065-02 | Third Party Advisory US Government Resource |
| https://www.schneider-electric.com/en/download/document/SEVD-2018-060-01/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-03-09 23:29
Updated : 2024-11-21 04:11
NVD link : CVE-2018-7239
Mitre link : CVE-2018-7239
CVE.ORG link : CVE-2018-7239
JSON object : View
Products Affected
schneider-electric
- atv340_dtm
- atv600_dtm
- atv_lift_dtm
- atv32_dtm
- atv71_dtm
- somove
- atv61_dtm
- atv12_dtm
- atv312_dtm
- atv320_dtm
- atv212_dtm
- atv900_dtm
- atv31_dtm
CWE
CWE-426
Untrusted Search Path
