First published: Mon Sep 07 2020(Updated: )
A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL.
Credit: CybersecurityCOE@eaton.com
Affected Software | Affected Version | How to fix |
---|---|---|
Eaton 9000x Programming And Configuration Software | <=2.0.38 |
Update the software to latest version available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6654 is a DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior.
The severity of CVE-2020-6654 is high, with a severity score of 7.8.
An attacker can exploit CVE-2020-6654 by replacing the required DLLs with malicious DLLs when the software tries to load vci11un6.DLL and cinpl.DLL.
The affected software of CVE-2020-6654 is Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior.
Yes, it is recommended to update to a fixed version of Eaton's 9000x Programming and Configuration Software to mitigate CVE-2020-6654.