SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-6478

Unitronics VisiLogic OPLC IDE before 9.8.02 does not properly restrict access to ActiveX controls, which allows remote attackers to have an unspecified impact via a crafted web site.

MEDIUM 6.8EPSS 1.55%

Does this matter?

Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.

Description

Unitronics VisiLogic OPLC IDE before 9.8.02 does not properly restrict access to ActiveX controls, which allows remote attackers to have an unspecified impact via a crafted web site.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
1.55% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
unitronics/visilogic oplc ide
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.