Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-10129

Опубликовано: 14 июл. 2026
Источник: fstec
CVSS3: 7.5
CVSS2: 6
EPSS Низкий

Описание

Уязвимость интегрированной среды проектирования Studio 5000 Logix Designer связана с недостатками процедуры авторизации. Эксплуатация уязвимости может позволить нарушителю выполнить произвольный код путем подмены файла конфигурации внешних инструментов

Вендор

Rockwell Automation Inc.

Наименование ПО

Studio 5000 Logix Designer

Версия ПО

до 32.05 (Studio 5000 Logix Designer)
до 36.00 (Studio 5000 Logix Designer)
до 35.01 (Studio 5000 Logix Designer)
до 34.02 (Studio 5000 Logix Designer)
до 33.02 (Studio 5000 Logix Designer)

Тип ПО

Сетевое средство

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)
Высокий уровень опасности (оценка CVSS 4.0 составляет 7,3)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1783.html

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 1%
0.0011
Низкий

7.5 High

CVSS3

6 Medium

CVSS2

Связанные уязвимости

nvd
18 дней назад

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

github
17 дней назад

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

EPSS

Процентиль: 1%
0.0011
Низкий

7.5 High

CVSS3

6 Medium

CVSS2