ID

VAR-201505-0421


TITLE

Elipse SCADA DLL Hijacking vulnerability

Trust: 0.8

sources: IVD: 6c9ec626-1e7f-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-02869

DESCRIPTION

Elipse SCADA is a web-based SCADA system that is deployed in important manufacturing, energy, hydraulic and other systems. The program has a DLL hijacking vulnerability when loading the DLL (the DLL pointed to is wfapi.dll), allowing an attacker to use the vulnerability to build a malicious application and place it in a specific path, which can cause the application to maliciously load the DLL and execute it

Trust: 0.72

sources: CNVD: CNVD-2015-02869 // IVD: 6c9ec626-1e7f-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 6c9ec626-1e7f-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-02869

AFFECTED PRODUCTS

vendor:elipsemodel:scada b141scope:eqversion:2.29

Trust: 0.6

vendor:elipsemodel:scada b141scope:eqversion:2.29*

Trust: 0.2

sources: IVD: 6c9ec626-1e7f-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-02869

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2015-02869
value: MEDIUM

Trust: 0.6

IVD: 6c9ec626-1e7f-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2015-02869
severity: MEDIUM
baseScore: 6.3
vectorString: AV:L/AC:M/AU:N/C:C/I:N/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 6c9ec626-1e7f-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 6.3
vectorString: AV:L/AC:M/AU:N/C:C/I:N/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 6c9ec626-1e7f-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-02869

TYPE

Code injection

Trust: 0.2

sources: IVD: 6c9ec626-1e7f-11e6-abef-000c29c66e3d

EXTERNAL IDS

db:CNVDid:CNVD-2015-02869

Trust: 0.8

db:IVDid:6C9EC626-1E7F-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 6c9ec626-1e7f-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-02869

SOURCES

db:IVDid:6c9ec626-1e7f-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2015-02869

LAST UPDATE DATE

2022-05-17T02:07:08.673000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-02869date:2017-01-22T00:00:00

SOURCES RELEASE DATE

db:IVDid:6c9ec626-1e7f-11e6-abef-000c29c66e3ddate:2015-05-06T00:00:00
db:CNVDid:CNVD-2015-02869date:2015-05-25T00:00:00