An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the simulator execute malicious code by redirecting the control flow of these instructions.
References
Link Resource
http://www.securityfocus.com/bid/93830 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-16-306-03 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2017-02-13T21:00:00

Updated: 2017-02-14T10:57:01

Reserved: 2016-09-28T00:00:00


Link: CVE-2016-8354

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-02-13T21:59:00.860

Modified: 2017-03-15T19:57:22.060


Link: CVE-2016-8354

JSON object: View

cve-icon Redhat Information

No data.

CWE