ID

VAR-201905-1341


TITLE

Display Control Remote HMI has dll hijacking vulnerability

Trust: 0.6

sources: CNVD: CNVD-2019-14866

DESCRIPTION

Shenzhen Xiankong Technology is a national high-tech enterprise specializing in R & D, production, sales and service of core products of Industry 4.0. Display Control Remote HMI has dll hijacking vulnerability. An attacker can maliciously load and execute a DLL by constructing a malicious application and placing it in a specific path. DLL And execute

Trust: 0.72

sources: CNVD: CNVD-2019-14866 // IVD: f8297a7a-d596-43bc-aa3c-127ae02f0191

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: f8297a7a-d596-43bc-aa3c-127ae02f0191 // CNVD: CNVD-2019-14866

AFFECTED PRODUCTS

vendor:display controlmodel:remote hmiscope:eqversion:v1.3.6

Trust: 0.6

vendor:xiankongmodel:display control remote hmiscope:eqversion:v1.3.6

Trust: 0.2

sources: IVD: f8297a7a-d596-43bc-aa3c-127ae02f0191 // CNVD: CNVD-2019-14866

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-14866
value: HIGH

Trust: 0.6

IVD: f8297a7a-d596-43bc-aa3c-127ae02f0191
value: HIGH

Trust: 0.2

CNVD: CNVD-2019-14866
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: f8297a7a-d596-43bc-aa3c-127ae02f0191
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: f8297a7a-d596-43bc-aa3c-127ae02f0191 // CNVD: CNVD-2019-14866

TYPE

Code injection

Trust: 0.2

sources: IVD: f8297a7a-d596-43bc-aa3c-127ae02f0191

PATCH

title:Display Control Remote HMI has dll hijacking vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/159977

Trust: 0.6

sources: CNVD: CNVD-2019-14866

EXTERNAL IDS

db:CNVDid:CNVD-2019-14866

Trust: 0.8

db:IVDid:F8297A7A-D596-43BC-AA3C-127AE02F0191

Trust: 0.2

sources: IVD: f8297a7a-d596-43bc-aa3c-127ae02f0191 // CNVD: CNVD-2019-14866

SOURCES

db:IVDid:f8297a7a-d596-43bc-aa3c-127ae02f0191
db:CNVDid:CNVD-2019-14866

LAST UPDATE DATE

2022-05-17T02:04:28.800000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-14866date:2019-05-22T00:00:00

SOURCES RELEASE DATE

db:IVDid:f8297a7a-d596-43bc-aa3c-127ae02f0191date:2019-05-21T00:00:00
db:CNVDid:CNVD-2019-14866date:2019-06-10T00:00:00