CVE-2017-5161 Information
Feb 14, 2021
cve
Description
An issue was discovered in Sielco Sistemi Winlog Lite SCADA Software versions prior to Version 3.02.01 and Winlog Pro SCADA Software versions prior to Version 3.02.01. An uncontrolled search path element (DLL Hijacking) vulnerability has been identified. Exploitation of this vulnerability could give an attacker access to the system with the same level of privilege as the application that utilizes the malicious DLL.
CVSS Vector
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/96119 https://ics-cert.us-cert.gov/advisories/ICSA-17-038-01
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: