An Uncontrolled Search Path Element issue was discovered in SIMPlight SCADA Software version 4.3.0.27 and prior. The uncontrolled search path element vulnerability has been identified, which may allow an attacker to place a malicious DLL file within the search path resulting in execution of arbitrary code.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-17-222-01 | us government resource third party advisory mitigation |
http://www.securityfocus.com/bid/100263 | vdb entry third party advisory |