Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loaded as an internal and valid DLL, which may allow arbitrary code execution.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-18-228-01 | third party advisory us government resource |
http://www.securityfocus.com/bid/105105 | third party advisory vdb entry |