Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2hf-2mmr-q63q

Опубликовано: 10 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.2
CVSS3: 8.2

Описание

CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent system when an authenticated user opens a malicious project file.

CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent system when an authenticated user opens a malicious project file.

EPSS

Процентиль: 14%
0.00227
Низкий

7.2 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.2
nvd
5 месяцев назад

CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent system when an authenticated user opens a malicious project file.

CVSS3: 8.2
fstec
5 месяцев назад

Уязвимость программного обеспечения для автоматизации производственных процессов EcoStruxure Automation Expert, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольные команды и получить полный контроль над системой

EPSS

Процентиль: 14%
0.00227
Низкий

7.2 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-94