Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfr5-cpm3-g35v

Опубликовано: 11 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

A vulnerability has been identified in TIA Portal V15 (All versions), TIA Portal V16 (All versions), TIA Portal V17 (All versions), TIA Portal V18 (All versions < V18 Update 1). Affected products contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system. If the user is tricked to open a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution.

A vulnerability has been identified in TIA Portal V15 (All versions), TIA Portal V16 (All versions), TIA Portal V17 (All versions), TIA Portal V18 (All versions < V18 Update 1). Affected products contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system. If the user is tricked to open a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution.

EPSS

Процентиль: 15%
0.00048
Низкий

7.3 High

CVSS3

Дефекты

CWE-20
CWE-22

Связанные уязвимости

CVSS3: 7.3
nvd
почти 3 года назад

A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions < V16 Update 7), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 6), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 1). Affected products contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system. If the user is tricked to open a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution.

CVSS3: 7.3
fstec
почти 3 года назад

Уязвимость среды разработки программного обеспечения систем автоматизации технологических процессов Totally Integrated Automation Portal (Portal TIA), связанная с возможностью обхода пути, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 15%
0.00048
Низкий

7.3 High

CVSS3

Дефекты

CWE-20
CWE-22