CVE Feed

    Dashboard / CVE / CVE-2017-14020

    CVE-2017-14020

    In AutomationDirect CLICK Programming Software (Part Number C0-PGMSW) Versions 2.10 and prior; C-More Programming Software (Part Number EA9-PGMSW) Versions 6.30 and prior; C-More Micro (Part Number EA-PGMSW) Versions 4.20.01.0 and prior; Do-more Designer Software (Part Number DM-PGMSW) Versions 2.0.3 and prior; GS Drives Configuration Software (Part Number GSOFT) Versions 4.0.6 and prior; SL-SOFT SOLO Temperature Controller Configuration Software (Part Number SL-SOFT) Versions 1.1.0.5 and prior; and DirectSOFT Programming Software Versions 6.1 and prior, an uncontrolled search path element (DLL Hijacking) vulnerability has been identified. To exploit this vulnerability, an attacker could rename a malicious DLL to meet the criteria of the application, and the application would not verify that the DLL is correct. Once loaded by the application, the DLL could run malicious code at the privilege level of the application.

    Published:Nov 13, 2017
    Last Modified:Apr 20, 2025
    EPS:Nov 13, 2017
    EPSS Score:0.00127
    CVSS Score:7.8

    Affected Products

    Vendor
    Automationdirect
    Product
    C-more Micro
    Vendor
    Automationdirect
    Product
    C-more Micro Firmware
    Vendor
    Automationdirect
    Product
    C-more Plc
    Vendor
    Automationdirect
    Product
    C-more Plc Firmware
    Vendor
    Automationdirect
    Product
    Click Plc
    Vendor
    Automationdirect
    Product
    Click Plc Firmware
    Vendor
    Automationdirect
    Product
    Gs Drives
    Vendor
    Automationdirect
    Product
    Gs Drives Fimware
    Vendor
    Automationdirect
    Product
    Sl-soft Solo Temperature Controller
    Vendor
    Automationdirect
    Product
    Sl-soft Solo Temperature Controller Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High