Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9108

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*
Версия до 32.05 (исключая)
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*
Версия от 33.00 (включая) до 33.04 (исключая)
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*
Версия от 34.00 (включая) до 34.04 (исключая)
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*
Версия от 35.00 (включая) до 35.02 (исключая)
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:36.00:*:*:*:*:*:*:*

EPSS

Процентиль: 3%
0.00134
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
github
2 месяца назад

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.

CVSS3: 6.7
fstec
2 месяца назад

Уязвимость интегрированной среды проектирования Studio 5000 Logix Designer, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю получить несанкционированный доступ на создание файлов и выполнить произвольный код

EPSS

Процентиль: 3%
0.00134
Низкий

7.5 High

CVSS3

Дефекты

CWE-22