Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-27858

Опубликовано: 27 окт. 2023
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using an uninitialized pointer in the application.  The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product.  The user would need to open a malicious file provided to them by the attacker for the code to execute.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rockwellautomation:arena:*:*:*:*:*:*:*:*
Версия до 16.20.02 (исключая)

EPSS

Процентиль: 23%
0.00075
Низкий

7.8 High

CVSS3

Дефекты

CWE-824
CWE-824

Связанные уязвимости

CVSS3: 7.8
github
больше 2 лет назад

Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using an uninitialized pointer in the application.  The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product.  The user would need to open a malicious file provided to them by the attacker for the code to execute.

CVSS3: 7.8
fstec
больше 2 лет назад

Уязвимость программного обеспечения для дискретного моделирования событий и автоматизации Rockwell Automation Arena, связанная с использованием неинициализированного указателя, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 23%
0.00075
Низкий

7.8 High

CVSS3

Дефекты

CWE-824
CWE-824