CVE-2018-7239

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
09/03/2018
Last modified:
26/03/2018

Description

A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in all versions prior to 2.6.2 which could allow an attacker to execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schneider-electric:atv_lift_dtm:*:*:*:*:*:*:*:* 12.7.0 (excluding)
cpe:2.3:a:schneider-electric:atv12_dtm:*:*:*:*:*:*:*:* 12.7.0 (excluding)
cpe:2.3:a:schneider-electric:atv212_dtm:*:*:*:*:*:*:*:* 12.7.0 (excluding)
cpe:2.3:a:schneider-electric:atv31_dtm:*:*:*:*:*:*:*:* 12.7.0 (excluding)
cpe:2.3:a:schneider-electric:atv312_dtm:*:*:*:*:*:*:*:* 12.7.0 (excluding)
cpe:2.3:a:schneider-electric:atv32_dtm:*:*:*:*:*:*:*:* 12.7.0 (excluding)
cpe:2.3:a:schneider-electric:atv320_dtm:*:*:*:*:*:*:*:* 1.1.6 (excluding)
cpe:2.3:a:schneider-electric:atv340_dtm:*:*:*:*:*:*:*:* 1.2.3 (excluding)
cpe:2.3:a:schneider-electric:atv600_dtm:*:*:*:*:*:*:*:* 1.8.0 (excluding)
cpe:2.3:a:schneider-electric:atv61_dtm:*:*:*:*:*:*:*:* 12.7.0 (excluding)
cpe:2.3:a:schneider-electric:atv71_dtm:*:*:*:*:*:*:*:* 12.7.0 (excluding)
cpe:2.3:a:schneider-electric:atv900_dtm:*:*:*:*:*:*:*:* 1.3.5 (excluding)
cpe:2.3:a:schneider-electric:somove:*:*:*:*:*:*:*:* 2.6.2 (excluding)