Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp2m-9jh8-h55h

Опубликовано: 14 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 9.1

Описание

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.

EPSS

Процентиль: 52%
0.00289
Низкий

8.7 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-22
CWE-287

Связанные уязвимости

CVSS3: 9.1
nvd
4 месяца назад

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость программного обеспечения создания и управления графическим интерфейсом оператора (HMI) на промышленных устройствах Rockwell Automation FactoryTalk View Machine Edition, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 52%
0.00289
Низкий

8.7 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-22
CWE-287