Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3q5h-r4qp-qqcg

Опубликовано: 30 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.

Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.

EPSS

Процентиль: 26%
0.00091
Низкий

7.8 High

CVSS3

Дефекты

CWE-610
CWE-73

Связанные уязвимости

CVSS3: 7.8
nvd
около 2 лет назад

Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.

CVSS3: 7.8
fstec
около 2 лет назад

Уязвимость программного обеспечения для программирования ПЛК Mitsubishi Electric GX Works3, программных средств управления приложениями для промышленных автоматизированных систем MELSOFT iQ AppPortal, MELSOFT Navigator и Motion Control Setting, позволяющая нарушителю выполнить произвольный код, раскрыть защищаемую информацию и вызвать отказ в обслуживании

EPSS

Процентиль: 26%
0.00091
Низкий

7.8 High

CVSS3

Дефекты

CWE-610
CWE-73