Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7j8p-86gv-324v

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.3

Описание

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

EPSS

Процентиль: 1%
0.0011
Низкий

7.3 High

CVSS4

Дефекты

CWE-863

Связанные уязвимости

nvd
18 дней назад

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

CVSS3: 7.5
fstec
18 дней назад

Уязвимость интегрированной среды проектирования Studio 5000 Logix Designer, связанная с недостатками процедуры авторизации, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 1%
0.0011
Низкий

7.3 High

CVSS4

Дефекты

CWE-863