First published: Wed Jun 12 2019(Updated: )
The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrusted search path that could execute a malicious .dll file not under the application's direct control and outside the intended directories.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Omron Network Configurator For Devicenet Safety | <=3.41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10971 is a vulnerability found in the Network Configurator for DeviceNet Safety 3.41 and prior, which allows the execution of a malicious .dll file not under the application's control.
CVE-2019-10971 has a severity score of 7.8, which is considered high.
Versions up to and including 3.41 of Omron Network Configurator for DeviceNet Safety are affected by CVE-2019-10971.
To fix CVE-2019-10971, it is recommended to update Network Configurator for DeviceNet Safety to a version higher than 3.41.
You can find more information about CVE-2019-10971 at the following link: https://ics-cert.us-cert.gov/advisories/ICSA-19-134-01