A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in all versions prior to 2.6.2 which could allow an attacker to execute arbitrary code.
References
| Link | Resource |
|---|---|
| https://www.schneider-electric.com/en/download/document/SEVD-2018-060-01/ | Vendor Advisory |
| http://www.securityfocus.com/bid/103338 | Third Party Advisory VDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-065-02 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-03-09 15:29
Updated : 2018-03-26 08:22
NVD link : CVE-2018-7239
Mitre link : CVE-2018-7239
JSON object : View
CWE
CWE-426
Untrusted Search Path
Products Affected
schneider-electric
- atv31_dtm
- somove
- atv61_dtm
- atv212_dtm
- atv_lift_dtm
- atv320_dtm
- atv600_dtm
- atv312_dtm
- atv12_dtm
- atv71_dtm
- atv340_dtm
- atv32_dtm
- atv900_dtm


