VYPR
High severity7.8NVD Advisory· Published Sep 30, 2020· Updated Jun 17, 2026

CVE-2020-6654

CVE-2020-6654

Description

A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL.

Affected products

3
  • cpe:2.3:a:eaton:9000x_programming_and_configuration_software:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:eaton:9000x_programming_and_configuration_software:*:*:*:*:*:*:*:*range: <=2.0.38
    • (no CPE)range: <=2.0.38
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.