PatchSiren

Sielcosistemi CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Sielcosistemi CVE published 2017-02-13

CVE-2017-5161

CVE-2017-5161 describes an uncontrolled search path element (DLL hijacking) issue in Sielco Sistemi Winlog Lite and Winlog Pro SCADA software. According to the CVE description, affected versions are those prior to Version 3.02.01, and successful exploitation could let an attacker run code with the same privilege level as the application that loads the malicious DLL. The record is associated with ICS-CERT [truncated]