Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j5j6-gp3m-h3vx

Опубликовано: 11 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.9

Описание

A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot.

A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot.

EPSS

Процентиль: 6%
0.00023
Низкий

8.9 High

CVSS4

Дефекты

CWE-200

Связанные уязвимости

nvd
3 месяца назад

A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot.

EPSS

Процентиль: 6%
0.00023
Низкий

8.9 High

CVSS4

Дефекты

CWE-200