Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-45p7-9xjf-9687

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.

A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.

EPSS

Процентиль: 57%
0.00349
Низкий

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.

EPSS

Процентиль: 57%
0.00349
Низкий

Дефекты

CWE-494