Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jpc-mpc7-cwp7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the transference of malicious code to the controller.

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the transference of malicious code to the controller.

EPSS

Процентиль: 64%
0.00473
Низкий

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the transference of malicious code to the controller.

EPSS

Процентиль: 64%
0.00473
Низкий

Дефекты

CWE-74