7
CVE-2017-5176
- EPSS 0%
- Veröffentlicht 19.05.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle ics-cert@hq.dhs.gov
- Teams Watchlist Login
- Unerledigt Login
A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and 9328-CCWDEVPTE; and Connected Components Workbench - Free Standard Edition (All Supported Languages), v9.01.00 and earlier. Certain DLLs included with versions of CCW software can be potentially hijacked to allow an attacker to gain rights to a victim's affected personal computer. Such access rights can be at the same or potentially higher level of privileges as the compromised user account, including and up to computer administrator privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rockwellautomation ≫ Connected Components Workbench SwEditiondeveloper Version <= 9.01.00
Rockwellautomation ≫ 9328-ccwdevdee Version-
Rockwellautomation ≫ 9328-ccwdevene Version-
Rockwellautomation ≫ 9328-ccwdevese Version-
Rockwellautomation ≫ 9328-ccwdevfre Version-
Rockwellautomation ≫ 9328-ccwdevite Version-
Rockwellautomation ≫ 9328-ccwdevpte Version-
Rockwellautomation ≫ 9328-ccwdevzhe Version-
Rockwellautomation ≫ 9328-ccwdevene Version-
Rockwellautomation ≫ 9328-ccwdevese Version-
Rockwellautomation ≫ 9328-ccwdevfre Version-
Rockwellautomation ≫ 9328-ccwdevite Version-
Rockwellautomation ≫ 9328-ccwdevpte Version-
Rockwellautomation ≫ 9328-ccwdevzhe Version-
Rockwellautomation ≫ Connected Components Workbench SwEditionfree_standard Version <= 9.01.00
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0% | 0.001 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7 | 1 | 5.9 |
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.2 | 1.9 | 10 |
AV:L/AC:H/Au:N/C:C/I:C/A:C
|
CWE-427 Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.