Description
A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malicious DLL. Local access is required to successfully exploit this vulnerability. This means the potential attacker must have access to the system and sufficient file-write privileges. If exploited, the attacker could place a malicious DLL file on the system, that when running XINJE XD/E Series PLC Program Tool will allow the attacker to execute arbitrary code with the privileges of another user's account.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21256 | A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malicious DLL. Local access is required to successfully exploit this vulnerability. This means the potential attacker must have access to the system and sufficient file-write privileges. If exploited, the attacker could place a malicious DLL file on the system, that when running XINJE XD/E Series PLC Program Tool will allow the attacker to execute arbitrary code with the privileges of another user's account. |
References
History
No history.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-09-16T17:24:14.853Z
Reserved: 2021-06-10T00:00:00.000Z
Link: CVE-2021-34606
No data.
Status : Modified
Published: 2022-05-11T15:15:08.420
Modified: 2024-11-21T06:10:48.097
Link: CVE-2021-34606
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD