CVE-2018-14797: High severity emerson deltav vulnerability
Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loaded as an internal and valid DLL, which may allow arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-14797?
CVE-2018-14797 is a vulnerability in Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 that allows a specially crafted DLL file to be loaded as an internal and valid DLL, which may allow arbitrary code execution.
How severe is CVE-2018-14797?
CVE-2018-14797 has a severity rating of 7.8 (high).
What software versions are affected by CVE-2018-14797?
Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 are affected by CVE-2018-14797.
How can CVE-2018-14797 be exploited?
CVE-2018-14797 can be exploited by placing a specially crafted DLL file in the search path and loading it as an internal and valid DLL.
Are there any references for CVE-2018-14797?
Yes, you can find more information about CVE-2018-14797 at the following references: - http://www.securityfocus.com/bid/105105 - https://ics-cert.us-cert.gov/advisories/ICSA-18-228-01