CVE-2017-7966: High severity schneider electric somachine vulnerability
Published Jun 7, 2017
·Updated
A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute arbitrary code on the targeted system. The vulnerability exists due to the improper loading of a DLL.
Affected Software
1 affected component
Schneider-electric Somachine=2.1.0
Event History
Jun 7, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7966?
CVE-2017-7966 is rated as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2017-7966?
To fix CVE-2017-7966, update Schneider Electric's SoMachine software to the latest version available.
3
What types of systems are affected by CVE-2017-7966?
CVE-2017-7966 affects systems running Schneider Electric's SoMachine version 2.1.0.
4
What can an attacker achieve with CVE-2017-7966?
An attacker exploiting CVE-2017-7966 can execute arbitrary code on the targeted system remotely.
5
Is CVE-2017-7966 easy to exploit?
Yes, CVE-2017-7966 can be exploited with relatively low skill, making it a significant security concern.