First published: Fri Nov 13 2015(Updated: )
Unitronics VisiLogic OPLC IDE before 9.8.02 does not properly restrict access to ActiveX controls, which allows remote attackers to have an unspecified impact via a crafted web site.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Unitronics VisiLogic | <=9.8.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6478 has a medium severity rating due to its potential impact on system integrity.
To fix CVE-2015-6478, upgrade to Unitronics VisiLogic OPLC IDE version 9.8.02 or later.
CVE-2015-6478 affects users of Unitronics VisiLogic OPLC IDE versions prior to 9.8.02.
CVE-2015-6478 allows remote attackers to exploit the vulnerability via a crafted website to access ActiveX controls.
Currently, the recommended action for CVE-2015-6478 is to update the software, as no reliable workaround is publicly documented.