CVE-2019-10981
Published May 31, 2019In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local user access to Citect user credentials.
Vendor/product archive
2 CVEs tagged to schneider-electric / scada_expert_vijeo_citect — 0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local user access to Citect user credentials.
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with versio…