CVE-2017-6033
7.8HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 7 April 2017
Summary
A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path.
Affected Version(s)
Schneider Electric Interactive Graphical SCADA System Software Schneider Electric Interactive Graphical SCADA System Software
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved