An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the simulator execute malicious code by redirecting the control flow of these instructions.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2017-02-13T21:00:00
Updated: 2024-08-06T02:20:30.802Z
Reserved: 2016-09-28T00:00:00
Link: CVE-2016-8354
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-02-13T21:59:00.860
Modified: 2024-11-21T02:59:12.550
Link: CVE-2016-8354
Redhat
No data.