Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7j8p-86gv-324v

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.3
CVSS3: 7.5

Описание

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

EPSS

Процентиль: 1%
0.00109
Низкий

7.3 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

CVSS3: 7.5
fstec
2 месяца назад

Уязвимость интегрированной среды проектирования Studio 5000 Logix Designer, связанная с недостатками процедуры авторизации, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 1%
0.00109
Низкий

7.3 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-863