Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj5f-6rc3-vgfv

Опубликовано: 24 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file system. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the Connected Components Workbench software. User interaction is required for this exploit to be successful.

The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file system. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the Connected Components Workbench software. User interaction is required for this exploit to be successful.

EPSS

Процентиль: 16%
0.00051
Низкий

8.6 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.7
nvd
почти 4 года назад

The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file system. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the Connected Components Workbench software. User interaction is required for this exploit to be successful.

CVSS3: 7.7
fstec
больше 4 лет назад

Уязвимость программного обеспечения проектирования и настройки контроллеров Connected Components Workbench (CCW), связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 16%
0.00051
Низкий

8.6 High

CVSS3

Дефекты

CWE-22