CVE-2021-34606
XINJE XD/E Series PLC Program Tool DLL Hijacking
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malicious DLL. Local access is required to successfully exploit this vulnerability. This means the potential attacker must have access to the system and sufficient file-write privileges. If exploited, the attacker could place a malicious DLL file on the system, that when running XINJE XD/E Series PLC Program Tool will allow the attacker to execute arbitrary code with the privileges of another user's account.
Se presenta una vulnerabilidad en XINJE XD/E Series PLC Program Tool en versiones hasta v3.5.1, que puede permitir a un atacante local autenticado cargar una DLL maliciosa. Es requerido acceso local para explotar con éxito esta vulnerabilidad. Esto significa que el atacante potencial debe tener acceso al sistema y suficientes privilegios de escritura de archivos. Si es explotado, el atacante podría colocar un archivo DLL malicioso en el sistema, que cuando sea ejecutado XINJE XD/E Series PLC Program Tool, permitirá al atacante ejecutar código arbitrario con privilegios de la cuenta de otro usuario
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-06-10 CVE Reserved
- 2022-05-11 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-427: Uncontrolled Search Path Element
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://claroty.com/2022/05/11/blog-research-from-project-file-to-code-execution-exploiting-vulnerabilities-in-xinje-plc-program-tool | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xinje Search vendor "Xinje" | Xd\/e Series Plc Program Tool Search vendor "Xinje" for product "Xd\/e Series Plc Program Tool" | <= 3.5.1 Search vendor "Xinje" for product "Xd\/e Series Plc Program Tool" and version " <= 3.5.1" | - |
Affected
|