ID

VAR-202012-1597


TITLE

Haiwell cloud configuration software Cloud SCADA has DLL hijacking vulnerability

Trust: 0.6

sources: CNVD: CNVD-2020-59817

DESCRIPTION

Haiwell Cloud Configuration Software Cloud SCADA is an industrial automation monitoring and management platform software based on .NET Framework developed by Xiamen Haiwell Technology Co., Ltd. Haiwell's cloud configuration software Cloud SCADA has a DLL hijacking vulnerability. Attackers can use this vulnerability to load malicious dlls and execute malicious codes.

Trust: 0.6

sources: CNVD: CNVD-2020-59817

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-59817

AFFECTED PRODUCTS

vendor:haiwellmodel:cloud configuration software cloud scadascope:eqversion:3.19.1.5

Trust: 0.6

sources: CNVD: CNVD-2020-59817

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-59817
value: HIGH

Trust: 0.6

CNVD: CNVD-2020-59817
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-59817

EXTERNAL IDS

db:CNVDid:CNVD-2020-59817

Trust: 0.6

sources: CNVD: CNVD-2020-59817

SOURCES

db:CNVDid:CNVD-2020-59817

LAST UPDATE DATE

2022-05-04T10:03:18.840000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-59817date:2020-11-02T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-59817date:2020-12-03T00:00:00