CVE-2021-38469
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD
Description
Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.
Affected (1)
Products: Auvesy: Versiondog
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.0.0 |
References (2)
Source: ics-cert@hq.dhs.gov
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Timeline
No history available yet.