CVE-2024-13946: Binary Planting / LoadLibrary DLL's not Signed
DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.; NEXUS Series: through 3.; MATRIX Series: through 3..
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13946?
CVE-2024-13946 has a medium severity rating due to its potential for exploitation through binary planting.
How do I fix CVE-2024-13946?
To fix CVE-2024-13946, ensure that all DLLs used with the ASPECT configuration toolset are digitally signed.
Which products are affected by CVE-2024-13946?
CVE-2024-13946 affects ASPECT-Enterprise, NEXUS Series, and MATRIX Series up to version 3.*.
What type of vulnerability is CVE-2024-13946?
CVE-2024-13946 is a binary planting vulnerability that arises from the lack of digital signature verification.
What are the risks associated with CVE-2024-13946?
The risks of CVE-2024-13946 include the possibility of malicious DLLs being loaded during device commissioning, leading to unauthorized actions.