Exploiting Vulnerabilities in XINJE PLC Program Tool
ID: c4d61302-4a7b-5820-be82-409700cebf38
STIX ID: report--c4d61302-4a7b-5820-be82-409700cebf38
Feed Name: Claroty Team82
Threat Score
Team82 disclosed two vulnerabilities in XINJE's PLC Program Tool (CVE-2021-34605 and CVE-2021-34606) where specially crafted .xdp project files exploit a zip-slip arbitrary write and subsequent DLL hijacking to achieve code execution on engineering workstations, potentially allowing attackers to compromise PLCs and disrupt OT processes; disclosure was delayed due to limited vendor cooperation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
