Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9425-qrrg-4g6q

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.3

Описание

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.

EPSS

Процентиль: 1%
0.00096
Низкий

7.3 High

CVSS4

Дефекты

CWE-428

Связанные уязвимости

nvd
18 дней назад

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.

CVSS3: 7.5
fstec
18 дней назад

Уязвимость модуля External Tools (Внешние инструменты) интегрированной среды проектирования Studio 5000 Logix Designer, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 1%
0.00096
Низкий

7.3 High

CVSS4

Дефекты

CWE-428