QID 590728
Date Published: 2022-03-21
QID 590728: Eaton 9000x programing and configuration software DLL Hijacking Vulnerability (ETN-VA-2020-1007)
Eaton 9000x Programming and Configuration software v 2.0.38 and prior is susceptible to DLL hijacking vulnerability.
An attacker can execute arbitrary code by replacing the vci11un6. DLL and cinpl.DLL when application tries to load the DLLs to perform normal operations.
Affected Products:
9000x programing and configuration software 2.0.38 and prior versions
QID Detection Logic:(Authenticated)
The QID uses registry to check the vulnerable version of 9000XDrive.exe.
Successful exploitation of this vulnerability may lead to arbitrary code execution.
Solution
The vendor has released 9000x version 2.0.41 to remediate this vulnerability.
Vendor References
CVEs related to QID 590728
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ETN-VA-2020-1007 |
|