Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xwxm-hg2j-hpjq

Опубликовано: 20 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.

Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.

EPSS

Процентиль: 10%
0.00037
Низкий

7.3 High

CVSS3

Дефекты

CWE-22
CWE-29

Связанные уязвимости

CVSS3: 3.9
nvd
почти 3 года назад

Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.

CVSS3: 9.3
fstec
около 3 лет назад

Уязвимость программного средства программирования ПЛК (программируемых логических контроллеров) Proficy Machine Edition, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 10%
0.00037
Низкий

7.3 High

CVSS3

Дефекты

CWE-22
CWE-29