CVE-2019-6825: High severity schneider electric proclima vulnerability
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL file, with the same name of any resident DLLs inside the software installation, to execute arbitrary code in all versions of ProClima prior to version 8.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Uncontrolled Search Path Element vulnerability in ProClima?
The vulnerability ID for the Uncontrolled Search Path Element vulnerability in ProClima is CVE-2019-6825.
What is the severity of CVE-2019-6825?
CVE-2019-6825 has a severity rating of 7.8 (high).
What is the affected software for CVE-2019-6825?
The affected software for CVE-2019-6825 is ProClima versions prior to 8.0.0.
What is the CWE category of CVE-2019-6825?
CVE-2019-6825 belongs to the CWE category 427: Uncontrolled Search Path Element.
How can the Uncontrolled Search Path Element vulnerability in ProClima be exploited?
The Uncontrolled Search Path Element vulnerability in ProClima can be exploited by a malicious DLL file with the same name as resident DLLs inside the software installation, enabling arbitrary code execution.